AnyConnect 3.1.x deployment to Mac OS X (10.8) clients.

I am using JAMF's Composer (a package building app) to repackage the AnyConnect 3.1 client with profiles to our Mac users.  The newly-created package installs and works fine.  But our AnyConnect clients are connecting to a Cisco ASA that is configured to use certificates for authentication.  AD user certificates are already on each computer.  Upon first launch, AnyConnect requests access to the System keychain (requiring admin credentials) and then it requests to sign the key "Configuration Profiles" in the user's keychain.  Does anyone know of a way to avoid these hassles?  Users do not have admin credentials. 
I would like it if we could push out AnyConnect and just have it work upon first launch.
Bob Reed

I found this on CCO.  If I am reading this correctly, "engine version" isn't supported on MAC OSX for SEP 11.x and 12.x.
Any thoughts on this?
http://www.cisco.com/en/US/products/ps10884/products_device_support_tables_list.html

Similar Messages

  • How to deploy connection (Mac OS X Yosemite to Windows RDS) through the RD Gateway with Two Factor authentication (Safenet OTP) on Session host?

    Good day!
    Could you please help me? How to deploy connection (Mac OS X Yosemite to Windows RDS) through the RD Gateway with Two Factor authentication on Session host? How to open an authentication dialog that is the same as in Windows when logging on to network resources
    in Windows (Windows Security)?
    Our test environment: We have one RDS 2012 R2 server (all roles in one) and one session host in collection. On the session host installed Safenet Network Logon and it under GPO which disable all authentication, only OTP.

    Hi Sir,
    It seems that you are going to integrate 3rd party product into AD for authentication .
    I would suggest you to contact the vendor of Safenet for this deployment  scenario  :
    http://www.safenet-inc.com/multi-factor-authentication/authentication-management/safenet-authentication-manager-express-samx/
    Best Regards,
    Elton Ji
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] .

  • MAC address of DB or Client machine

    Dear,
    Can U please tell me how to get MAC address of Database or Client Machine via PL/SQL or routine used in PL/SQL envoirment.
    Thanks
    FAHAD AZIZ KHAN

    To get the MAC the simplest way would be to issue a HOST or CLIENT_HOST command to run ipconfig /all, redirecting the result of that to a file and then use the relevant TEXT_IO to read the output and pull out the Physical Address line.
    You'll just have to be careful on machines with multiple adaptors or virtual adaptors (such as VPN drivers) to pick the right one.

  • HT5361 Where on my hard drive are my Mac OS 10.9 Mail Client emails stored?

    Where on my hard drive are my Mac OS 10.9 Mail Client emails stored?

    If you want to make your user library remain visible, go to Finder and select your user/home folder. With that Finder window as the front window, either select Finder/View/Show View options or go command - J.  When the View options opens, check ’Show Library Folder’. That should make your user library folder visible in your user/home folder.
    Thanks to leonie for some information contained in this.
    This will probably need to be repeated after an update.

  • How to get MAC Address for maintaning unique client id at server side?

    Hi All,
    Can somebody tell how can i get MAC id for maintaing Unique client id at server.
    or is there any alternative way to do this?
    Thanks in advance..
    CK

    Usually people just use cookies for that.

  • How to configure the mac mini to allow the clients to access both partitions...the client will only see the one we are logged into at the server???

    if possible??? how do we configure the mac mini to allow the clients to access both partitions...the client will only see the one we are logged into at the server???

    You have to explicitly share directories on external/secondary volumes.
    Use the Server admin app to configure file sharing, and select which directory/directories on the second drive you want to share, then they'll be available to clients.

  • Using MDT 2013 for deploying Software from MDT Server to PC Client automatically and silently ?

    I have a trouble about deploying software from MDT 2013 server to PC Client , Can we using MDT 2013 for deploying software automatically and silently , that Users/Clients don't have to click "next,next" to install software ?
    If you have a solutions to deploying it , please share me about that solutions ?
    Thanks.
     

    you can make software silently with boot opción:
    with chocolatey opensource.
    or make software with switches
    here link to help you:
    http://blogs.itpro.es/octaviordz/2014/05/29/instalando-aplicaciones-con-chocolatey
    http://blogs.itpro.es/octaviordz/2014/06/05/integrando-chocolatey-a-mdt-2013-e-instalando-aplicaciones-de-forma-desatendida-en-windows-8-1/
    http://blogs.itpro.es/octaviordz/2014/10/31/probando-chocolatey-en-windows-10
    http://blogs.itpro.es/octaviordz/2012/07/10/aplicaciones-desatendidas
    MVP Jesús Octavio Rdz http://blogs.itpro.es/octaviordz

  • Hi.  I'm trying to set-up the wireless access times in my Airport Utility.  I need to enter the "Description" and the "MAC Address" of each wireless client before I assign access times. What are these?  Thanks.

    Hi.  I'm trying to set-up the wireless access times in my Airport Utility.  I need to enter the "Description" and the "MAC Address" of each wireless client before I assign access times. What are these?  Thanks.

    Let's say that an iPhone is one of the wireless clients that you want to allow access to the network.
    The Description of this device is anything that you want to specify for easy identification purposes. For example, the Description might be something like......
    Rex's iPhone
    The MAC Address, also known as a Wi-Fi Address is  a unique indentifiction number that is assigned to every device. The number will always follow this form:
    xx : xx : xx : xx : xx : xx, where "x" could be a number or letter.
    To find the MAC Address or Wi-Fi Address of an iPhone or iPad.....
    On the Home screen.....
    Tap Settings
    Tap General
    Tap About
    Wi-Fi Address is the item that you want
    If you have a Mac computer......you can find the MAC Address or Wi-Fi Address as follows:
    Open System Preferences (gear icon on the dock)
    Open Network
    Click on Wi-Fi on the left
    Click Advanced at the lower right
    The Wi-Fi Address for the Mac is located at the bottom of the window
    Other wireless devices usually have the MAC Address or Wi-Fi Address on the label on the back or bottom of the device

  • I have InDesign 3 Version 5.0 for Mac. I have a client with a PC who has either InDesign 6 or CC for PC. If I sell him usage rights to my files, will he be able to use them?

    I have InDesign 3 Version 5.0 for Mac. I have a client with a PC who has either InDesign 6 or CC for PC. If I sell him usage rights to my files, will he be able to use them?

    ...but from what I have read general practice is to charge extra for native files as you are giving over usage rights of the artwork.
    Not a lawyer, just been around the block before. It all sort of depends on the client and understandings on both your parts, whether in writing or not. What is their expectation while they were paying you? What was your expectation during the same period? In lieu of an agreement, I think the courts would side on the client's rights.
    But regardless, I generally do what Peter wrote unless there is an agreement in writing stating otherwise. One of the reasons why I happily turn over client work is because sometimes the new-hire or new contractor simply doesn't work out and I am often called back into the mix. It's goodwill.
    Mike

  • AnyConnect 3.1.04059 installer for Mac wipes /opt folder

    The Mac OSX installer for AnyConnect 3.1.04059 has been wiping the whole /opt folder during the install process.  This is bad especially if you use MacPorts or anything else that uses that folder.
    I have seen this happen several times and it's definitely the AnyConnect installer.  Has anyone else seen this?
    Anyway, back up your opt folder before installing!
    NBB

    The problem is with FIPS (Federal Information Processing Standard). On default ASA disables it but in 3.1.04066 OSX client there's a bug that forces it on. FIPS wont accept default self-signed certificates and prevents the connection.
    To fix the issue, upgrade or downgrade your client. Currently newest version is 3.1.04072 that also has some improvements for OSX 10.9
    The root of the problem is still the default self-signed certificate that anyconnect uses. This might also cause annoying security warning pop-ups whenever a user connects to an ASA with these default certificate settings.
    Check this, Example Set 3, Scenario C.
    http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect20/administrative/guide/admin2.html#wp1000596
    Had the same problem and this is my impression of the reasons for this problem. Someone can correct me if there's any mistakes.

  • How can I repackage Adobe Air and updates to it in PKG format for deployment to Macs?

    We have about 200 Macs in our organization and do push deployments to them using JAMF Casper (which requires that installers be in PKG format).  I am periodically asked by our security department to apply updates to Adobe Air for security reasons.  So my question is  - how can I repackage the AIR installer and updates to PKG format so I can deploy them from Casper? 
    I've looked at Adobe Application Manager Enterprise Edition - and it doesn't even recognize the AIR installer as an Adobe installer.
    Any info you can provide would be much appreciated.
    Bob Reed
    AARP

    You might be able to do this by creating a bootstrapping application to launch the installer.  Here's some documentation on distributing AIR in enterprise environments along with a link to our distribution agreement.
    http://www.adobe.com/products/air/runtime-distribution1.html
    http://help.adobe.com/en_US/air/redist/WS485a42d56cd19641-70d979a8124ef20a34b-8000.html

  • 802.1x deployment with MAC filtering

    Hi All
    I read "Enhance your 802.1x deployment security with MAC filtering" on NAP blogs with link as below.
    http://blogs.technet.com/nap/archive/2006/09/08/454705.aspx
    I am wondering this tip might not be correct somehow and would like to know how to imployment it correctly.
    First of all, there is only a "Verify Caller ID" field in "dial-in" tab of user properties, not "Calling Station ID". I tried to add MAC address in this field and the authenticaiton works.
    As the description of the tip, we can add multiple MAC addresses in that field but it doesn't work. I tried to use
    "AA-BB-CC-DD-EE-FF | BB-AA-FF-EE-DD-CC" format as multiple MAC address and IAS always responce error with wrong calling staiton ID. Does anyone know how to correctly add multiple MAC addresses in "Verify Caller ID"?
    Thanks

    Hi Sam
    Thank you for your reply.
    I would like to explain why I want to use multiple MAC addresses authenticaiton for an account on a singel AD.
    Genereally, 802.1X can be imploymeted for wired and wireless authenticaiton on many network devices in a company or entriprise. An employee in a company or entriprise is supposed to have only one account but might have multiple devices such as a PC, laptop, or PDA. For the convenience of authenticaiton imployment, I think I should only create an account for that person and make a MAC filtering for any devices he is autrorized to use.
    I had tried the first example you mention but it didn't work. The switch and wireless gateway I used for test only sent one MAC address (calling station  ID) to AD and AD only recognized the first MAC address of all MAC addresses I key in. Of course, your example can be succesful if the device sends multiple MAC addresses simultaneously because AD thinks the those "MAC addresses" is just one string or one calling staiton ID. But that's is not what I want.
    Anyway, I will try the second way you suggest.
    Thanks a lot.

  • Deploy in mac

    Hi
    i have developed my aplication on a PC but in my mannual I want tell how to deploy my application on a Mac 10.1
    Since i have not use a Mac before, can someone give me some information on how to deploy on a Mac

    No, it is for deploying applications, ofton over the web, but it could be from CD http://java.sun.com/products/javawebstart/

  • Deployment to Mac App Store

    Hello,
    does anybody have an experience what is the best method for packaging application (non-JavaFX) for Mac App Store?
    I have found that it is possible to use AppBundler for doing that but then I found that JavaFX packaging tools can be used https://blogs.oracle.com/talkingjavadeployment/entry/packaging_improvements_in_jdk_7#3.
    Also how is it with including Oracle JRE? Is it possible to include it from license perspective or OpenJDK has to be used?
    Thanks,
    Anicka

    Most likely you will have to uninstall the old version and then purchase the App Store version.  That's what happened with Growl. 
    Plus, when purchased through the App store, unless it's free, Apple will be making money from hosting the App and it's subsequent updates.  Therefore, they will want their piece of the pie.  So, if you have already purchased and then you want the App Store to maintain it, then you will probably have to re-purchase it.
    My assumptions, but pretty sturdy.  Try asking the iTunes support, but they aren't very helpful.  They mainly just direct you to long legalize speak.    

  • Anyconnect 3.102026 failes to install - MAC

    System:  Macbook AIR, 10.8.2.
    After an upgrade of the OSX to version 10.8.2,  the Cisco client fails to install. We receive an error message that the program failed to install. If i try to start the cisco anyconnect secure mobility client it says "No component loaded. Quitting application". Other applications installs without error on the computer.
    The error message from the console-log says "Ask for assistance from the softwareproducer". Any idea what this could be?

    Try downloading the package for new installs. the update package failed, but the new install package worked for me without any trouble.
    History:
    I began this trouble shooting exercise by selecting Download Only through the Apple Update applet. Running the msi manually did not resolve the problem. In fact, it was more frustrating because the download package would disappear after running even though it failed, and I had to download it again. "Cleanup" I suppose. <frown>
    I followed advice to remove the Apple Software Update program, reboot and re-run the msi. That did not resolve the failure.
    I then followed advice to set permissions for Administrators on registry key HKLM\Software\Micorosoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Com ponents
    then reboot and run the update msi again. This also did not resolve the failure.
    I downloaded the installer from the Apple download site as though it were a fresh install, and - voila! - it installed correctly and all content and settings were preserved. Hopefully that is all that is needed, not the steps above. Let me know! http://www.apple.com/itunes/download/

Maybe you are looking for

  • How do i restore an external hard drive pc backup to a mac

    Can anybody expelling to me how to restore a PC backup to my new iMac please? I have a full backup of my PC on an external USB hard drive but I can't work out how to restore it onto my Mac. Thanks!

  • How do download my video without a fire-wire port??

    How disappointing! Just discovered the lack of a FireWire port on my new MBP when I started to download video from my Sony Camcorder. What now?? Been looking for an adapter with a USB 3.0 or a hub, but to no avail. There is a cord with USB on one end

  • HT5299 Can I connect a wii to the Thunderbolt?

    I'm about to purchase a wii but don't have a tv.  Can someone explain what I need to purchase so I can connect the wii to the Thunderbolt display?  There's so much conflicting information and I'm not a techie at all! 

  • Oracle 9.2 installation error message on window XP:

    Hi all; I am new to oracle and try to install oracle 9.2 on window XP professional. Everything went well except the error message: Tehre is no non empty value found for variable j_Servport in \oracle\ora92\Apache\Apache\ports.ini Here is the content

  • Opening Balanced

    I've a new company code (IPW). Before i start to use transaction with CoCd (IPW), I've input the opening balanced. Can you explain step by step how to input the opening balanced in FICO and is there any customizing in IMG should i run for Opening Bal