April 5, 2004 OS X Lab Image Meeting Attendance: Dave Pugh, Jan Stewart, Jeff Kopmanis, Todd Austin, Gretchen Kopmanis, Scott Lemm Handling mail: Now: Kerberos? Machines come by default as LSA kerberos machines BETTER YET FOR A GREATER CONCENSUS -- RUN A POLL TO ALL DEPTS ASKING WHICH WAY THEY'D PREFER. WE'RE GETTING FLACK FROM FOLKS (UNJUST, IMO) THAT WE AREN'T TAKING OTHER DECISIONS INTO CONSIDERATION. MY RESPONSE, COME TO THE MEETING! ASK AT LUMA(?) MAINTAIN TWO PKGS, AT LEAST UNTIL THE REALMS COLLAPSE - lab mtg consensus: create a 2nd pkg for UMICH kerberos SSL? Pops up a warning about SSL cert d.imap != species.imap Options: 1) Leave it as is (SSL warning pops up) -- WE'LL DO THIS 2) Turn SSL off (only if authenticating with Kerberos) 3) Modify loginhook to set server to final server (species) - disadvantage: if d.imap->species.imap mapping changes, user's email will break 4) is there a way to fake the system into thinking the warning acceptance has been checked Multiple packages: - Kerberos + SSL (gkk will use [more secure]) - Kerberos + no SSL (Todd will use [easier for users]) - no Kerberos + SSL (Jeff K will use [mixes with LSA kerberos]) (enable SSL on outbound mail?) remove "Do you want to see what's new in Mail" dialogue Mulberry? (for familiarity sake -- as used in Sites/BlueDisk) Jan's ball & chain login.term too -- name them Terminal.login.term or somesuch... so they'll sit next to Term.app -- Utilities LUMA DISCUSSION: Arguments about modifying the dock -- word, excep powerpoint, etc are 98% used. RADMIND DEMO from last week: potential firewall issues after demo, gkk tried setting up her own radmind server and was not successful - implies it needs more documentation Status: LDAP - (currently manual install) done and tested Kerberos Login - (currently on rotten) done and tested homedirectory contents link to AFS - not done desktop link to Windows homespace - done, not tested? needs to be posted Manage home folder - done and tested Logout button - More Ball & Chain for Jan OFW - no Jeremy present Managed printing - PRINTING STILL CONTINUES TO BE A PROBLEM need to document how to create printer config file and ppd for individual lab environments and their local-environment printers. Possibly create a loginhook that creates this list and locks the print queue (??) Create the template, and package it, then, if you need to, remove whatever printers you won't need set restrictive perms on the PrintCenter.app #! /bin/sh # Set the printer to front desk /bin/cp /private/etc/cups/printers.conf.LRC_Front_Desk /private/etc/cups/printer s.conf /bin/rm -rf /private/etc/cups/ppd/* /bin/cp /private/etc/cups/ppd.disabled/LRC_Front_Desk_on_lrc_prmc2_lrc_lsa_umich _edu.ppd /private/etc/cups/ppd/ /usr/bin/killall -9 cupsd /usr/sbin/cupsd LUMA DISCUSSION: who will eventually have access to SNI? eg. Physics making non-DSA's "deputies" for SNI loads