NetBoot/NetInstall settings in Server Admin buggy as ****?

Hi,
I administer a Mac pool in College. We recently updated to all new iMacs (except for one, which still is a 2006 C2D iMac) and Leopard Server running on a PowerMac G4 (Dual 1GHz, 1.5 GB RAM).
Except for a few initial quirks with Directory Services, Leopard Server runs fine and snappy on the G4 and seems highly reliable. But then again, there's this BIG problem with NetInstall.
We setup one of the new iMacs as the master computer with all the neccesary software installed, and then created a NetInstall image from it using System Image Utility. It took a while, but went fine.
We then placed the image in the proper directory (Library/NetBootSP0), and configrured and launched NFS and NetBoot services in Server Admin. It found the image and offered configuration for it. But somehow, the most essential settings are not saved, when clicking "Save" in server admin, no matter whether the service is still running or being stopped before settings are changed.
These settings are saved by Server Admin:
Default image
Enable this image
Diskless (while not being available)
Architecture (Universal, Intel or PPC)
Protocol (NFS or HTTP)
While these settings *are not* saved by Server Admin whatsoever:
Model property filtering ("Allow any Apple Computer" vs. "Allow only specified models")
MAC Address filtering ("Allow only listed clients and deny others" vs. "Deny listed clients and allow all others")
(These settings appear when selecting an image from the list an clicking on the Edit-button (with a pen on it))
Whenever I make a change to this and click "Save", Server Admin simply ignores this and reverts it to the default settings, which are "Allow any Apple Computer" an "Allow only listed clients and deny others" with no clients listed.
When I leave the setting on "allow listed and deny others" (Whitelist), an add a clients MAC Address and save, this is ignored by Server Admin.
When I change the setting to "deny listed and allow others" (Blacklist), and save, this is ignored by Server Admin too. No matter whether I add MAC Addresses to the blacklist or not.
That way, the NetBoot service will *not send my NetInstall Image to any client*, because it thinks it has a whitelist configured, that is permanently empty. Clients not added to the whitelist are denied, which is good, but it is not possible at all, to even add a client to that whitelist. Blacklisting some machine and allowing all others doesn't work either.
Editing the approproate NBImageInfo.plist manually showed me, that Server Admin is able to:
read settings for specified types of models properly, but unable to change this setting
and *unable to even read settings about whitelisted or blacklisted MAC addresses* from the plist (keys "EnabledMACAddresses" or "DisabledMACAddresses") properly.
And so, it also cannot write these settings into the plist, it seems.
I have to NetInstall the classroom until thursady, and because of this bug, I cannot get it to work as it should, since all my cients are denied the image. This is very frustrating.
What can I do?
Message was edited by: jamespsullivan

MAC address filtering at the server level works, just not filtering at the image level. Depending on exactly what you are trying to achieve, this might help. But, I'm not clear on exactly what you are trying to achieve with the filtering.
The 1,0 syntax is mostly irrelevant. It is simply a reference to the NIC on the connecting system. If you have a machine with multiple NIC's (such as a Mac Pro) you might see something like 2,0:xx... instead. Regarding the rest of it, I believe the Server admin will accept accept any MAC address in the format of xx:xx:xx:xx:xx:xx with or without leading 0's (i.e. 00:0a:1b vs. 0:a:1b).
Model filtering information is stored in the NBImageInfo.plist, and can be manually tweaked with an appropriate application of force. You can manually move system types that you want enabled into the EnabledSystemIdentifiers list (and, of course, remove them from the DisabledSystemIdentifiers list).

Similar Messages

  • Mac OS X Leopard Server (PPC) "forgets" settings if Server Admin is left on

    I'm not sure that I'm posting this question in the right place.
    I have a QuickSilver 2001 Power Macintosh G4 (867MHz, 2x120GB PATA hard drives, 1.5GB RAM) running a fully up-to-date copy of Mac OS X Server 10.5.2. The hardware appears to be in good shape. The disks are new and I'm very certain the RAM is good. Apple Hardware Diagnostics finds no problem with the computer itself.
    Normally, this system is very reliable. It works as a primary domain controller for Windows PCs. However, if by some chance I forget to close the Server Admin application, and the machine sits for a while without use, Server Admin will claim that "no services are configured" when I return. I also saw this problem on the 10.5 and 10.5.1 releases.
    The services really do appear to stop working when this happens. I have Open Directory, DNS, DHCP and SMB configured. All four will stop responding.
    Rebooting the computer usually gets the services going again, and Server Admin will then function properly. However, I always have to reconfigure SMB to be a primary domain controller.
    Any ideas? Since this is just a test system, I did try wiping the disks and doing a reinstallation. The problem persisted.
    I think this may be PowerPC specific, as I have an Intel Mac mini set up much the same way (Mac OS X 10.5.2 server, 4GB RAM, 320GB hard disk) and it does not appear to suffer from this issue.

    Yes, I just discovered this problem on my own machine.
    I just wanted to check some settings and discovered that the behaviour of the GUI of Server Admin was somewhat "erratic": First this "no services are configured" message. Some of the configured servers were marked with the usual green "up and running" bullet, others dark grey - those were normally configured and running and clicking the appropriate line seemed to force Server Admin to check the actual state and then turned also green. But sometimes configuration pages were "greyed out", or while switching through the tabs Server Admin claimed that where were "unsaved changes" which should be saved (or discarded).
    And then SMB: this was light grey, as usual when a service is not running and clicking on it I browsed through the configuration tabs - everything seemed ok (all my settings were correctly shown, configured as PDC with right domain name etc.) - and I started the service. Then suddenly the configuration settings changed to the default settings - no more PDC, but a "standalone server" with workgroup name "WORKGROUP"...
    Looks for me, as if Server Admin lost it's "source" file for the configuration (the file in /var/db/smb.conf says, that it is automatically generated -- does somebody were the source file is stored?)...

  • Server Admin buggy

    Hi all
    In the logging tab of web pane's server admin, I don't have any format available.
    Of course, I can enter the format but…
    Any one else have already seen it ?
    Thanks for your help
    Fredol

    It would be helpful to know what version you are running.
    So -- if you are running 10.5.2, first off you will want to consider cloning your working drive to a separate volume, then running all updaters. The server would be (as of today) at 10.5.4 and the SA would be at 10.5.3.
    Also note that I've seen this absence of default settings on a clean test installation, so it appears to be a bug/feature Apple's Server dev group has introduced recently. It shows up haphazardly -- I can't see a pattern as two why one server will not have it but others will. Servers that were updated from Tiger OSXS do NOT seem to exhibit this bug -- but I only have a sampling of 10 or so machines, so that might not be right.
    You should see: Other (%h %l %u %t "%r" %>s %b) which appears to be the Apple default, or one of these other four:
    combined %h %l %u %t "%r" %>s %b "%{Referer}i" "%{User-Agent}i"
    common %h %l %u %t "%r" %>s %b
    referer %{Referer}i -> %U
    agent %{User-agent}i
    these are part of the modlogconfig.so (look for logconfigmodule in your SA:Web:Settings:Modules section and make sure that is enabled).
    Use the Server Admin feedback feature to tell Apple about this and any other bug or badly-crafted 'feature' in the SA. Don't wait for someone else to do it -- they need to know, and they don't do much with the information in these forums. If you have Applecare, call in the bug and whine until they fix it (in 10.5, not 10.6).

  • Export settings within Server Admin doesn't really

    So I've had a whootin good time with a migration. Situation was a dual g4 died on me, right after I'd imaged it to a mac mini. I have another mac mini that I wanted to setup as a backup machine/tester. I tried one time to export all the server settings and admin settings and that didn't work at all, so I decided to export say...just my firewall settings, then import just the firewall settings back in. That worked, but didn't have all my firewall settings (ended up having to copy ipfw.conf.apple over). I then tried the same with just dns settings, but that didn't work..I'd import in, the zones would flash up on the zone list, then vanish. Has anyone ever successfully exported and imported settings? So far it's seemed like kind of a waste of time if it's not gonna copy everything over. I dunno...maybe it's the g4 imaged to the macmini that I'm exporting from. All of these are on 10.5.6 using the latest build of Server Admin

    Have a look at the following:
    http://support.apple.com/kb/TS3960

  • VPN Settings Server Admin L2TP PPP Authentication Kereberos option dimmed?

    Hi. I set up my 10.4 server as an open directory master. Kerberos works on the LAN for single signon.
    I am trying to configure VPN service now. When I go to the "Settings" section of VPN in Server Admin, under L2TP, "PPP Authentication", MS-CHAPv2 is selectable but "Kerberos" is dimmed, i.e. I can't select it. What do I need to do to be able to used Kerberos here?
    Thanks,

    Thanks BrianFL. This helps hugely. Yes, I just to set up a simple filesharing VPN not the kind of VPN that bypass Internet censorship. I use ethernet connection directly from my router yes.
    1. I just need to use the server app to set up a VPN and port forwarding. That is it?
    2. The setting I have made according to the guide with Server Admin Tools seems never going away, even after I deleted the server that has all the settings inside Server Admin Tools. Upon creating a new server inside Server Admin Tools, the new server inherits all the settings from the one I just deleted. Any idea how I can restore to Server Admin Tools's defaults settings?
    3. Even VNC (I use RealVNC) on the mini stopped working after I made changes according to the guide and deleted all the changes I can find. What is the address format for lion's build in VNC (192.168.0.100:5800?) like? I forgot how it is.
    Thanks so much!

  • Server Admin permissions

    Hi, where do I change the permissions to allow certain users to edit server settings (e.g. NetBoot settings) in Server Admin?

    A user needs to be in the Administrator group in order to run Server Admin and configure a server.
    Note that this can have other consequences - since it makes the user an admin they can change any element of the server, not just the components exposed by Server Admin.

  • Mail Server Relay Authentication Failure in Server Admin

    I need to set up Mail Server to relay through my ISP.  I know that I can authenticate to smtp.comcast.net:587 using my account and TLS usnig a mail client.
    However, when I use Server Admin to configure my server's SMTP to send all outgoing email through this relay (Server Admin>Mail>Settings>General>
    Rely outgoing mail through host: smtp.comcast.net:587
             Authenticate to rely with user name: user
    I get the SMTP error:
    SASL authentication failed: cannot authenticate to server smtp.comcast.net[76.96.62.117]: no mechanism available
    There are no toggles on Server Admin to specify TLS or SSL or anything for authentication.
    Does anyone know how to tell Server Admin how to authenticate an SMTP relay to smtp.comcast.net using TLS, which is apparently what comcast expects?

    Wow, this is an obscure solution, but it works. According to this thread, the problem is that:
    Although Comcast advertises "AUTH LOGIN PLAIN", the Postfix SASL library won't do plain text auth by default. It needs to be told it's okay with:
    smtp_sasl_security_options = noanonymous
    Solution:
    $ su -
    $ cd /etc/postfix
    $ cp main.cf main.cf.no_smtp_sasl_security_options
    $ echo 'smtp_sasl_security_options = noanonymous' >> ./main.cf
    $ serveradmin stop mail
    $ serveradmin start mail
    I'm not sure how often /etc/postfix/main.cf is overwritten, but presumably this happens every time you change and save Mail settings in Server Admin, so you must redo these steps every time you change the Mail server if you want to use smtp.comcast.net as your mail relay.
    AAPL, would you please add a toggle to handle this in Server Admin?

  • Lion server VPN + Server Admin Tools 10.7

    Hi,
    I followed this guide http://macminicolo.net/lionservervpn to try to set up VPN on my lion mac mini server.
    I also used Server Admin Tools 10.7 as instructed in the guide.
    After completing the steps in the guide, I cannot get VPN to work, plus I have extra problems as below:
    my mini cannot connected to the Internet or local network shares. I found under "Network" setting there was extra VLan created by the system automatically showing as "System Test--Connection error". After I delete this extra connection and revert my Ethernet to its original settings I can connect to the Internet again.
    Server Admin Tools 10.7 seem to retains all its settings from the guide on NAT, Firewall etc. doesn't matter if I had removed the current server and created a new server in the left pane. Is there anyway I can restore the Server Admin Tools to its programme defaults? I suspect these settings are affecting my networks and I cannot get rid of them completely. 
    Would VPN still work if I just set it up in the server app? I haven't been able to get it work this way. I also want to find out is your guide for using the VPN to connect to the Internet off the server as a way to bypass restrictions? Do I have to set it up this way as the guide if I just to want to set up a VPN for simple fireshareing?
    What did this command in the guide do to my mini? I was hopping if I cannot get VPN to work, then I should at least reverse the effects of this command. How do I undo this command please? "sudo serveradmin settings vpn:Servers:com.apple.ppp.l2tp:DNS:OfferedServerAddresses:_array_index:0 = "192.168.2.1"

    Thanks BrianFL. This helps hugely. Yes, I just to set up a simple filesharing VPN not the kind of VPN that bypass Internet censorship. I use ethernet connection directly from my router yes.
    1. I just need to use the server app to set up a VPN and port forwarding. That is it?
    2. The setting I have made according to the guide with Server Admin Tools seems never going away, even after I deleted the server that has all the settings inside Server Admin Tools. Upon creating a new server inside Server Admin Tools, the new server inherits all the settings from the one I just deleted. Any idea how I can restore to Server Admin Tools's defaults settings?
    3. Even VNC (I use RealVNC) on the mini stopped working after I made changes according to the guide and deleted all the changes I can find. What is the address format for lion's build in VNC (192.168.0.100:5800?) like? I forgot how it is.
    Thanks so much!

  • Using spamtrainer then Server Admin

    I've run spamtrainer and followed all the instructions included with it and all looks well...
    I believe I remember reading in some of those instuctions that I should stay clear of changing settings with Server Admin once I've using spamtrainer.
    Is it safe to change the "Minimum junk mail score" setting in Server Admin? What are the settings (or is it just any of them) that one should refrain from changing in Server Admin after running spamtrainer?
    By the way pterobyte, if you are the one that answers, thanks for all your posts and for spamtrainer.

    Alan,
    spamtrainer does NOT limit your use of Server Admin in any way whatsoever.
    What you probably read somewhere is that you should ditch Server Admin once you start manually modifying postfix and amavisd configuration files.
    Yes it is safe to change the score in SA.
    Alex
    P.S. You are welcome

  • How do NetBoot/NetInstall clients report connection & progress to server

    We've got rather tight access controls on our networks at my uni and one things I've noticed is we don't get the Connection and Progress information from NetBoot/NetInstall clients that you normally see in Server Admin. Does anyone know how is info is sent back to the server so we can reconfigure our access controls. My guess is its some sort of multi-cast but I need more info.

    It's a Bonjour broadcast.
    bnesse5:~ brian$ dns-sd -B netbootclient.tcp .
    Browsing for netbootclient.tcp
    Timestamp A/R Flags if Domain Service Type Instance Name
    11:38:45.329 Add 2 4 local. netbootclient.tcp. NetBoot011

  • Server Admin cannot update any mail settings on nearly fresh 10.4 server

    I can no longer use the Server Admin application to change settings under Mail (and I need to make some changes - would like to change logging settings and require authentication for SMTP). I made some initial settings with no problems, but now it chokes...
    For example, I click on Mail, Settings, Advanced... and then try to click the box to require Kerberos Authentication for SMTP-- everything is normal until I hit SAVE. Then there is a delay of 10 or 15 seconds, followed by the error message:
    "A connection with a server or service was lost. Try to disconnect from XServe.local and then reconnect, or contact your network administrator."
    At this point the mail indicator is red, not green... after clearing the message the changes I've made to settings appear intact, but if I quit server admin the truth comes out... I'm asked would I like to save changes, if I say yes the error will repeat-- I have to quit without saving. Relaunching Server Admin reveals that indeed the changes have not been made.
    I've heard of this type of problem when hand editing config files, but I've not done that with any mail-related files (I made two minor changes to a http config file a while ago, otherwise it's all been through Server Admin).
    Is there any way to reset the mail-related files so that Server Admin will return to life, or do I have to reformat the drive and reinstall OS X 10.4.4 hoping it doesn't happen again?
    By the way, the problem started a few days ago, and the upgrade to 10.4.4 didn't magically cure it.

    I'm having the same problem (and updating to 10.4.5 did not fix it either).
    In my case, it takes 30 seconds for the "A connection with a server or service was lost." to come up; I have a lot of mailing lists, and was wondering if it was some sort of timeout value on the server admin server end. (I hope that Server Admin doesn't write out every mailing list's membership every time you change any Mail setting!)
    You can make some changes using the serveradmin command line tool. For example, I noticed this problem when trying to turn on log-rolling.
    First, to find the appropriate command:
    sudo serveradmin settings mail > mailsettings
    I grepped for "log":
    grep "log" mailsettings | grep -v mailman
    (grep -v mailman drops any mailman settings, such as all of the users where "log" appears in their e-mail address)
    And found:
    mail:postfix:logrolling_daysenabled = no
    I then ran the command:
    sudo serveradmin settings mail:postfix:logrolling_daysenabled = yes
    to turn log rolling on. Quitting Server Admin and getting back into it showed that logrolling_daysenabled was enabled.
    So that might be a temporary solution for simple changes.
    In my case, this is a very fresh server: purchased and put into play over a period of three weeks. It worked until I copied the mailing lists over, but a small number of mailing lists copied did not trigger the error. This is what leads me to believe there is some kind of timeout happening.
    Jerry

  • "Settings" has disappeared in Server Admin

    After upgrading both of my Xserve G4's from OS X Server 10.4.8 to 10.4.9, I noticed when Server Admin is connected to one of the servers, the "Settings" button when you select the server does not appear. I also don't get information back about the system version, computer name, system start time, etc. The rest of Server Admin appears to work correctly, though. I was wondering if anyone else had this problem.
    Regardless of which system I run Server Admin from, when I select the "working" server in Server Admin I see tabs for Overview / Logs / System / Graphs / Update / Settings, for the "unhealthy" server I only see tabs for Overview / Logs / System / Graphs / Update. In addition, no valid information is shown in the Overview tab (as shown below).
    Luckily, I do have a workaround. Although the Server Admin GUI doesn't appear to be functioning correctly, the serveradmin CLI tool works fine. I'm wondering what the 10.4.9 update might have clobbered. Disk Verify / Repair Permissions haven't turned up any problems.
    HEALTHY Overview:
    System Version: Mac OS X 10.4.9 (Build 8P135)
    Server Version: Mac OS X Server 10.4.9 (Build 8P135)
    Computer Name: xxxx
    Local Hostname: xxxx.local
    Default AppleTalk Zone: Unspecified
    License Type: Unlimited-client license
    System Start Time: Sunday April 1, 2007 9:51:12 AM America/Phoenix
    UNHEALTHY Overview:
    System Version: Not available
    Server Version: Not available
    Computer Name: Not available
    Local Hostname: Not available
    Default AppleTalk Zone: Not available
    License Type: Not available
    System Start Time: Date and time not available

    Yes, in many cases you can still use commands via the Terminal, see Apple's Command-Line Administration guide
    http://www.apple.com/server/documentation/
    I would look through your logs. If you launch /Applications/Utilities/Console , it should open the last log written to.
    See about enabling the debugging menu in Server Admin. Quit out of SA, and in the Terminal enter:
    defaults write com.apple.serveradmin UseDebugMenu YES

  • Change SMB settings (sharepoint, status, etc.) with Server Admin

    Hi. Big problems with Server Admin to administer SMB service with Mac OS X Server 10.5.2.
    When you share a sharepoint, you set the enable oplocks and enable strict locking as you want and when you save, all your settings disappear. Fix with modifying directly /etc/smb.conf.
    Worse. My server "B" is connected to an ODM "A". No problem with Open Directory / Kerberos except when I try to bind the SMB Service to the PDC. When you choose Domain Member, the setting is automatically reverted to Standalone (nothing's visible in the log with the status change). When you choose Latin 1 850, the setting goes back to Latin US 437.
    I'm lost.
    Any experience ?
    Best regards.

    I have a Leopard Server 10.5.2 and it's a PDC. Same problem with strict locking and Code Page Latin US 437.
    Doing many tests I found this solution to the code page problem that seem to be a sync problem of the Server Admin.
    Try this but remember to do a backup of your files!!
    To change the SMB Code Page, modify the smb service default configuration file:
    sudo pico /System/Library/CoreServices/SmbFileServer.bundle/Resources/ServerDefaults.plis t
    Set:
    <key>DOSCodePage</key>
    <string>CP437</string>
    To:
    <key>DOSCodePage</key>
    <string>CP850</string>
    Save in pico with ctrl+x and Restart SMB Service in server admin.

  • Netboot/Server Admin problems

    Hi,
    I'm using 10.6.8 server and for a while now server admin has disallowed any user to log in to manage the server. I now want to deploy an old 10.6 image and need to re-enable netboot, does anyone have the terminal command as i have forgotten it and cant remember it at all
    Regards.
    Jim.

    sudo serveradmin start netboot

  • Server Admin Crashes: Thread 6 NetBoot

    Every time I start my Server Admin Program it crashes and cannot update the services and cannot load some of them.  When I click on DHCP I know it is running but it will show no connected clients. Netboot Will Not Even Populate.
    I get several errors:
    My Server:
    OS X Server 10.5.8
    Server Admin Tools: 10.5.3 (even though I used the 10.5.7 install package.)
    The Service has encountered an error (kNetworkError)
    DHCP:
    missing '}' at line 34444
    when I run a status update
    NETBOOT:
    From system log:
    com.apple.servermgrd: Exited Abnormally: Bus Error
    NETBOOT: (continued)
    Problem From Log:
    Process:    
    servermgrd [22059]
    Path:       
    /usr/sbin/servermgrd
    Identifier: 
    servermgrd
    Version:    
    Code Type:  
    X86 (Native)
    Parent Process:  launchd [1]
    Date/Time:  
    2013-02-17 11:14:03.979 -0500
    OS Version: 
    Mac OS X Server 10.5.8 (9L34)
    Report Version:  6
    Anonymous UUID:  5BD50A1F-4C6D-4787-8490-FCBA1C6993F9
    Exception Type:  EXC_BAD_ACCESS (SIGBUS)
    Exception Codes: KERN_PROTECTION_FAILURE at 0x0000000000000000
    Crashed Thread:  6
    Thread 6 Crashed:
    0   com.apple.CoreFoundation          0x9761672b CFBooleanGetValue + 43
    1   ...rverAdmin.servermgr_netboot    0x0043c273 my_xdrproc + 12873
    2   ...rverAdmin.servermgr_netboot    0x00439915 my_xdrproc + 2283
    3   libservermgrcommon.dylib          0x00077414 -[PluginRequestHandler doProcessInputWithRequest:context:lockFileFD:] + 315
    4   libservermgrcommon.dylib          0x000791c0 -[BundleManager doCommand:withModule:forUser:] + 905
    5   libservermgrcommon.dylib          0x00078ba7 -[BundleManager doOneBatchCommand:] + 448
    6   com.apple.Foundation              0x93006dfd -[NSThread main] + 45
    7   com.apple.Foundation              0x930069a4 __NSThread__main__ + 308
    8   libSystem.B.dylib                 0x97fe0055 _pthread_start + 321
    9   libSystem.B.dylib                 0x97fdff12 thread_start + 34

    Your NFS mounts (and service) appear to be fine.
    Looking at your screenshot, you have a much larger problem than NetBoot & DHCP. The whole servermanager daemon looks like it's failing to run.
    You are probably going to have to get someone to diagnose it live, or take it to an Apple Store.

Maybe you are looking for

  • Latest update issues

    Since downloading the latest update I have been experiencing these issues: Calendar events take a few seconds to upload. All events disappear, then reappear. Often loose connection to cellular network. Only solution is power off and restart phone. Ne

  • Finding a rogue WiFi router on local network

    This is likely a very odd and possibly complicated question, but I figure I'd throw it out there anyways. At my office, we have a couple wireless routers throughout the building. However, one in particular has started to act up. It used to work perfe

  • Todate function issue

    Hello all, I'm trying to implement todate() fucntion in the repository but not able to have it working correctly. I defined the chronological keys for the levels in the time dimension. The report should look like the following: months|number of repor

  • Unable to install to iOS 5.1.1

    Hi...I just to know why my iPhone can't install the new iOS 5.1.1. With an error setting ....

  • IIOP timeout setting??

    I have a client that calls an EJB using IIOP through a servlet. It connects fine and I can see the bean "working" on the server side. After 60 seconds, the client receives the following error: java.rmi.MarshalException: CORBA COMM_FAILURE 1 Maybe; ne