Friday, August 12, 2011

OS X Lion not creating a local home folder for network users

Update: 3/27/12


After a few months of relying on Snow Leopard, I had to get a new Macbook so this topic has come back up. I'm happy to report that the 10.7.3 update Apple released in early February appears to have fixed the mobile account issue this post was about. The only thing that still doesn't work is when disconnected from the network, domain users do not have admin rights on the machine even if they're in a group that Directory Utility has identified as an admin group on the machine. To get around this, check out my other post.


Update: 8/19/11
Apple released 10.7.1 yesterday, so I'm curious to see if it resolves these issues with network accounts. I'll have a chance to test it next week and will update this with what I find. If you're ready this and already tried it please leave a comment as to whether or not it works for you

Original Post

I use local home folders for the Mac users I manage, but the Macs are bound to Active Directory for the user accounts. In OS X 10.7 Lion this seems to be far from complete. First I couldn't get logged in with a network account, which required a workaround. Then after getting in, another error said the "The home folder for user xxxxxx isn't located in the usual place or cannot be accessed". This has worked fine in 10.4-10.6 but is now broken in 10.7. The problem appears to be related to OS X Lion having bugs with creating mobile accounts. By unchecking "Create mobile account", the home folder issue disappears. Supposedly I see a lot of talk of a 10.7.2 update fixing this problem, but since that update is in beta and not available to the general public that doesn't do much good. If you don't know where to go to uncheck the mobile account box, here's a walkthrough:


1. Open System Preferences
2. Go to User & Groups
3. Click Login Options in the lower left. You may have to authenticate first by clicking the lock icon in the lower left.
4. Under Network Account Server, click Edit
5. Select your domain, then click Open Directory Utility
6. Select Active Directory, then click the pencil to edit
7. Click to Show Advanced Options
8. Under User Experience you will see "Create mobile account at login". Uncheck this box
9. Click OK
10. Close your windows
11. Reboot and log in like normal

"Network accounts are unavailable" when logging into OS X Lion

Update: 3/27/12

I essentially gave up with the Mac Mini waiting on an update that solves the problem, and apparently 10.7.3 completely flew under my radar. I had read 10.7.2 still had issues, but in 10.7.3 one of the primary bugs Apple says they fixed is authentication with directory services. I had to get my first new Mac in a while this past weekend and was going to back rev it to run Snow Leopard, which turns out to be a pain. If you're looking to do it, check this article. Essentially you need a second Mac running Lion in order to use Target Disk Mode to install Snow Leopard on the machine.

In the testing I did today after updating to 10.7.3, it appears that both mobile accounts and the network unavailable issue have been fixed. The network unavailable may still show up for a little bit, but it disappeared for me within a minute. Having mobile accounts working also makes it easier since after the first login the user won't need to wait for the network account availability to change.

Update: 8/19/11
Apple released 10.7.1 yesterday, so I'm curious to see if it resolves these issues with network accounts. I'll have a chance to test it next week and will update this with what I find. If you're reading this and already tried it please leave a comment as to whether or not it works for you

Original Post


If you use Active Directory user accounts with your Macs, you may run into this issue after upgrading or introducing OS X Lion. Hopefully Apple comes out with an update to fix it soon, but in the meantime there is a workaround. You can add a custom search path to the Authentication tab and that seems to work. Here's a walkthrough:

1. Open System Preferences
2. Go to User & Groups
3. Click Login Options in the lower left. You may have to authenticate first by clicking the lock icon in the lower left.
4. Under Network Account Server, click Edit
5. Select your domain, then click Open Directory Utility
6. At the top, select Search Policy
7. Under the Authentication tab you should see two paths: /Local/Default, and /Active Directory/YourDomain/All Domains, where YourDomain is a placeholder for the name of your domain name. Click the + to add another
8. You should see /Active Directory/YourDomain listed as an additional option. Select it and click Add
9. Move /Active Directory/YourDomain above /Active Directory/YourDomain/All Domains so it has a higher priority
10. Click Apply
11. Reboot and log in

Thanks to juiced2010 at macrumors.com for posting that the solution.

Thursday, August 11, 2011

Mac OS X 10.7 Lion scrolling is inverted

After having my first hands-on experience with Mac OS X 10.7 Lion, one thing I noticed right away is that Apple thought it was a good idea to try to change the way people use scroll buttons on mice. They've set the default to be inverted, so if you scroll down the screen moves up, and scrolling up the screen moves down. I I'd guess this is because of their new swipe gestures to control your computer, but for someone like me who likes a two-button mouse it makes scrolling seem backwards. It's a simple fix though if your preferences are the same as mine:

1. Open System Preferences
2. Go to Mouse
3. Uncheck the box at the top that says "Move content in the direction of finger movement when scrolling or navigating"
4. Close System Preferences

Thursday, July 14, 2011

"Security log on this system is full" error when logging in

If you're logging in to a Windows XP or Windows Server 2003 machine and you notice this message, it's a really simple fix assuming you have access to an admin account on the machine. If not, you won't be able to login until it gets resolved, so contact an admin. Here's how to fix it:

1. Login using an account with admin privileges on the machine in question
2. Right-click My Computer, then go to Manage
3. Go to Computer Management->System Tools->Event Viewer
4. Right-click on Security and select Properties
5. In the Log Size section, do one of the following:

  • Increase the maximum log size. This will avoid the error message until your log reaches the new maximum, but you won't lose record of any security log events
  • Select Overwrite events as needed. This will maintain the log up to the maximum size, and then delete the oldest events when it needs more space
  • Click the Clear Log button in the lower right. This will wipe out all records in your security log
6. Click OK

That takes care of the problem. You'll want to make sure to choose the best option for what you'd like to accomplish, and can use a combination such as increasing the log size and overwriting events as needed.

Wednesday, June 22, 2011

OS X Disk Utility restore failed "Must be imagescanned..." error

While trying to image some Macbook Pros I ran into a problem restoring the prepared image onto the Macbooks. Disk Utility said the image file needed to be imagescanned in order to continue. I didn't know what this meant, but luckily this turned out to be something very simple. If you get this error select your image file you plan to restore, then go to Images->Scan Image for Restore.. in the top menu bar. That will run a quick check on your image file and allow you to restore it once the scan is finished.

Wednesday, May 11, 2011

Turn Fn or function key lock on or off on newer HP laptops

Update 12/8/2020:

While this post is over 9 years old at this point, I did run across a similar issue with the Fn keys being needed on a new HP Probook 450 G5. I'm not sure if the BIOS setting mentioned below still exists, but you can enable the Fn lock to get at your F1-F12 keys on that device by holding down the Fn key and then pressing the left shift key and releasing both at the same time.

Original Post:

I purchased a stack of Compaq Presario CQ56-115DX laptops the other day because they were super cheap and fit their purpose almost perfectly. However, it would require using the F1-F12 keys a lot. I found that out of the box, you had to hold down Fn in order to do that. By default the special actions on each key was used instead. I did some searching trying to find a way to lock the function keys and luckily I was able to find one. HP calls them Action Keys, and it's a BIOS setting. Disabling Action Keys allows you to use F1-F12 by default, and enabling it lets you adjust the brightness, change the volume, etc without needing to hold Fn. You can find the official HP document here. Otherwise here's how to do it:

1. Turn on the computer
2. Press F10 as soon as you see the HP or Compaq splash screen. This should take you into the BIOS
3. Once the BIOS settings load, go to System Configuration using the arrow keys
4. Press the down key to get to Action Keys
5. Press F5 or F6 to toggle between Enabled/Disabled. Enabled will change the brightness or change volume, disabled will allow using F1-F12
6. Press F10 to save the settings and exit

Thursday, April 7, 2011

"File does not have program associated with it" when trying to run any application in Windows

Update 11/21/2011:


After receiving a comment regarding this not working in the Run As Administrator mode, I did a quick search and found a Microsoft FixIt post that has a fix it for me option. You can find that link here: http://support.microsoft.com/kb/950505. If you can get the automatic fixer tool to run then that should clear up your problem, otherwise this article also lists the manual steps you can use to clear it up.


Original Post:

I had a user bring in a personal machine today (running Vista) and ask why she couldn't open anything on her computer. Immediately I told her she was likely infected with something, and it turns out she was. I used Spybot and MalwareBytes Anti-Malware to clear the infection. If you're not familiar with adware removal, check out one of my early posts. Afterward she was left with an error when trying to open anything. It said "This file does not have a program associated with it for performing this action. Please install a program or, if one is already installed, create an association in the Default Programs control panel." For those of you who are more visual, it looked like the image below.


If you have this error don't bother with the Default Programs control. Instead, I found a Microsoft KB article that outlines the steps that worked for me, which you can find here. I used a slightly modified version, which is what I'll explain here. My version is specific to Vista and should work on Windows 7, but likely won't work for XP. If you have XP or run into problems with my method, feel free to check out the KB article for the official walkthrough. Or there's another KB article listed here.

1. Open My Computer and go to C->Windows
2. Find regedit.exe, right-click and choose Run As Administrator. This will open the registry editor

Be careful to only change what is listed below from this point forward. Any other changes to the registry could potentially screw up the computer and require an OS restore.

3. In the left-hand pane, navigate to HKEY_CLASSES_ROOT->exefile->shell->open->command. In my case the command key wasn't there so I had to create it. If you are missing command, right-click open, select New Key, then type command there. This will create the command sub-key for you to click on.

4. In the right-hand pane, double click on (Default) that is listed inside command

5. Change the Value data field to "%1" %* exactly like that. To be clear that is quote then percent then 1 then quote then space then percent then asterisk

6. Click OK

7. Close Registry Editor

Now you should be able to open your applications again.

Tuesday, February 15, 2011

Add custom field to tickets and email in osTicket 1.6

I recently installed osTicket 1.6 for our property management group to use and have need to make some customizations. One of those customizations was how to create a custom field and add it to the tickets so more data could be captured. While the instructions to do this are out there, they seem to be located in different spots, so I'm going to try to consolidate a few useful links here for you.

How to add the custom field to the form

Making a custom field usable within the email templates (this is my own posted solution)

Listing a custom field in the Open Ticket table on the staff page (this doesn't explain exactly how to show a custom field, but does list the steps needed to add a field to the staff Open Tickets view)

Show the custom field in the ticket info on the staff side
I don't remember where I found the instructions for how to do this, but it's pretty simple. Edit the /include/staff/viewtickets.php file and insert the following where you want the custom field to be displayed

fieldName
getFieldName()?>

Wednesday, February 9, 2011

Remove orphaned Windows installer files to free up space

Using Microsoft's msizap.exe utility, found in the Windows Standard Development Kit (Windows SDK), you can clean up orphaned installer files from your C:\Windows\Installers directory. I recently found 10GB of orphaned installers using this method on an XP Pro machine, and it was nice to free up that space for other uses. Here's how you check to see if you have any orphaned installers taking up unnecessary space on your machine. If you're not sure what is taking up the unnecessary space, check out my previous post which should help you track it down.

1. Download the Windows SDK from Microsoft
2. Install the Windows SDK
3. Go to Start->All Programs->Microsoft Windows SDK->CMD Shell
4. Type "msizap.exe G!" and press enter. This will search for and remove orphaned installer files without the need for you to enter anything else
5. Once it finishes, close the command prompt window and go back to what you were doing

Monday, January 17, 2011

Deploying Quicktime fails with "A newer version of Quicktime is already installed"

UPDATE 10/13/2011: iTunes 10.5 doesn't require Quicktime to run anymore, so hopefully this problem disappears, but if you're still having trouble this article should help. If this doesn't solve your problem you can also try using the Windows Installer Cleanup Utility. Microsoft pulled this from it's list of available downloads citing the potential for problems (so this is your warning), but MajorGeeks.com still hosts a copy and that's where the link above will take you. Download and install the utility, then run it and remove any references to Quicktime it finds. You may even find some other unneeded programs leftover that you didn't see in the Add/Remove Programs list. After removing the Quicktime entries try running your modified installer that you create using the directions below.

Original Post

I ran into this issue while trying to deploy iTunes using group policy. Luckily a little digging in the msi file led me to a quick fix through the use of a transform of the original msi. If you have an easier fix please share in the comments. In order to do this you'll need Orca (which you can get from here), or another MSI editor installed. This should work on a personal machine as well, but you likely don't have a Quicktime.msi file yet so you'll want 7-zip installed in this case. Here's what I did that worked for me

If you don't have a Quicktime.msi file, start here. Otherwise skip to step #3 if you already have it, whether through iTunes or as a standalone

1. Download Quicktime from Apple

2. Right-click the QuickTimeInstaller.exe file and select 7-zip->Extract to QuickTimeInstallere. This will create a folder named QuickTimeInstaller containing some files, one of which is the Quicktime.msi that you need.



3. Open Orca, then go to File->Open, and browse out to your Quicktime.msi file

4. In the Tables column on the left, find the entry named "InstallExecuteSequence" and click on it.


5. On the right-side, look for "PreventDowngrade" in the actions column. This should be set to 1. Change this value to 0


6. Now save your newly modified .msi file


7. Close Orca and run the modified version of Quicktime.msi.

This should allow Quicktime to overwrite whatever other information it may be finding on your computer, which will bypass the error and get your Quicktime install back in working order.