<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Mike O'Connor</title>
	<atom:link href="http://www.haven2.com/index.php/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.haven2.com</link>
	<description>Mike O'Connor - St Paul, MN - geek entrepreneur type guy</description>
	<lastBuildDate>Tue, 17 Jan 2012 23:26:57 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>Comment on Adding capabilities to Mac OS X Lion Server by Mike O'Connor</title>
		<link>http://www.haven2.com/index.php/archives/adding-capabilities-to-mac-os-x-lion-server/comment-page-1#comment-40764</link>
		<dc:creator>Mike O'Connor</dc:creator>
		<pubDate>Tue, 17 Jan 2012 23:26:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/?p=816#comment-40764</guid>
		<description>hi Conrad,

thanks for the kind words, and the &quot;-R&quot; tip (i shoulda RTFM the man page on that -- doh!)

before wiping altogether, know that you can also reset the Open Directory stuff.  i have instructions for doing that from the terrific Tier-2 support person, but he asked me not to republish his email.  so before you wipe the machine and start over, i&#039;d give Apple a call.  they want lots of reassurance that you know what you&#039;re doing (this blog post was helpful in that regard) but once you&#039;ve convinced the Tier 1 person that you do, they push you along to some really great folks in Enterprise support if you&#039;re still inside your 90 day free support window.  i&#039;m thinking of buying the Apple Care deal just so i can extend that privilege out to 3 years.  $129 is starting to look like a pretty good deal.  

i haven&#039;t completed my testing yet -- i may have to reset my Open Directory stuff too, in which case i&#039;ll publish the step-by-step here. 

mikey</description>
		<content:encoded><![CDATA[<p>hi Conrad,</p>
<p>thanks for the kind words, and the "-R" tip (i shoulda RTFM the man page on that -- doh!)</p>
<p>before wiping altogether, know that you can also reset the Open Directory stuff.  i have instructions for doing that from the terrific Tier-2 support person, but he asked me not to republish his email.  so before you wipe the machine and start over, i'd give Apple a call.  they want lots of reassurance that you know what you're doing (this blog post was helpful in that regard) but once you've convinced the Tier 1 person that you do, they push you along to some really great folks in Enterprise support if you're still inside your 90 day free support window.  i'm thinking of buying the Apple Care deal just so i can extend that privilege out to 3 years.  $129 is starting to look like a pretty good deal.  </p>
<p>i haven't completed my testing yet -- i may have to reset my Open Directory stuff too, in which case i'll publish the step-by-step here. </p>
<p>mikey</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Adding capabilities to Mac OS X Lion Server by Conrad</title>
		<link>http://www.haven2.com/index.php/archives/adding-capabilities-to-mac-os-x-lion-server/comment-page-1#comment-40763</link>
		<dc:creator>Conrad</dc:creator>
		<pubDate>Tue, 17 Jan 2012 22:49:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/?p=816#comment-40763</guid>
		<description>Mike - 

Nice write-up. I&#039;ve been  having some major issues with my Lion Server install. I had Snow Leopard client and had all these same things running there, but like you, wanted the &#039;simplicity&#039; of the branded server implementation. It&#039;s been a bit of an uphill battle.  

One little note - to change the ownership of a folder and all of its contents, you can add the &quot;-R&quot; flag (applies the change recursively to all files and folders in the named folder) to your chown command:
sudo chown -R _www your-site&#039;s-foldername

That might be the only advice I can offer - I have so badly messed up my server that I lost pretty permalinks in trying to move my site and allow for virtual hosting.  But besides that I know that when I set it up, I erred in how I set up Open Directory and the users associated with it. So I&#039;m planning on just starting all over - wiping clean (after backing up important files, of course) and starting fresh. I appreciate your efforts here - it&#039;s great reference!

One last comment - I would have thought that toggling the web on and off in server.app would re-write some of the config files that you edited, including the httpd.conf file, and possibly the site-specific config files. But it would seem it did not for you. That&#039;s somewhat encouraging...! 

Thanks for sharing your experiences here!</description>
		<content:encoded><![CDATA[<p>Mike - </p>
<p>Nice write-up. I've been  having some major issues with my Lion Server install. I had Snow Leopard client and had all these same things running there, but like you, wanted the 'simplicity' of the branded server implementation. It's been a bit of an uphill battle.  </p>
<p>One little note - to change the ownership of a folder and all of its contents, you can add the "-R" flag (applies the change recursively to all files and folders in the named folder) to your chown command:<br />
sudo chown -R _www your-site's-foldername</p>
<p>That might be the only advice I can offer - I have so badly messed up my server that I lost pretty permalinks in trying to move my site and allow for virtual hosting.  But besides that I know that when I set it up, I erred in how I set up Open Directory and the users associated with it. So I'm planning on just starting all over - wiping clean (after backing up important files, of course) and starting fresh. I appreciate your efforts here - it's great reference!</p>
<p>One last comment - I would have thought that toggling the web on and off in server.app would re-write some of the config files that you edited, including the httpd.conf file, and possibly the site-specific config files. But it would seem it did not for you. That's somewhat encouraging...! </p>
<p>Thanks for sharing your experiences here!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Comments/Questions by Cole</title>
		<link>http://www.haven2.com/index.php/home/comment-page-1#comment-39801</link>
		<dc:creator>Cole</dc:creator>
		<pubDate>Tue, 27 Dec 2011 17:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/index.php/home/#comment-39801</guid>
		<description>Mike,  Your welcome

i have to say i never thought about the corp.com   being an issues for corp internal websites aka FQDN (aka adding corp at the end of it).    i can see now by adding a wild card for corp could cause major issues.

Your domain generics was a good buy up in the 90&#039;s (wish i had thought of it. 

cole</description>
		<content:encoded><![CDATA[<p>Mike,  Your welcome</p>
<p>i have to say i never thought about the corp.com   being an issues for corp internal websites aka FQDN (aka adding corp at the end of it).    i can see now by adding a wild card for corp could cause major issues.</p>
<p>Your domain generics was a good buy up in the 90's (wish i had thought of it. </p>
<p>cole</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Comments/Questions by Mike O'Connor</title>
		<link>http://www.haven2.com/index.php/home/comment-page-1#comment-39799</link>
		<dc:creator>Mike O'Connor</dc:creator>
		<pubDate>Tue, 27 Dec 2011 14:20:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/index.php/home/#comment-39799</guid>
		<description>Woops.  Mis-linked AND out of alphabetical order.  Thanks for the heads up Cole -- fixed now.

I have lots of other domains -- but they aren&#039;t super-premium generics like those.  They&#039;re things like APrairieHaven.com, BugLunch.com, BlipTrips.com.  Goofy names, some of which have web sites, some that are just crazy ideas.</description>
		<content:encoded><![CDATA[<p>Woops.  Mis-linked AND out of alphabetical order.  Thanks for the heads up Cole -- fixed now.</p>
<p>I have lots of other domains -- but they aren't super-premium generics like those.  They're things like APrairieHaven.com, BugLunch.com, BlipTrips.com.  Goofy names, some of which have web sites, some that are just crazy ideas.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Comments/Questions by Cole</title>
		<link>http://www.haven2.com/index.php/home/comment-page-1#comment-39783</link>
		<dc:creator>Cole</dc:creator>
		<pubDate>Tue, 27 Dec 2011 03:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/index.php/home/#comment-39783</guid>
		<description>Mike,   ran across your page via accident but i read over your domain page and found an error in the linking to corp.com

7. Do you have other domains?

This is a generic page, so I don&#039;t know which domain you got here from. Here&#039;s a list of the names that get a lot of hits;

Corp.com
Bar.com 

corp.com and bar.com Hotlink is one hotlink not 2   if you click corp or bar it takes you to bar.   

Cole</description>
		<content:encoded><![CDATA[<p>Mike,   ran across your page via accident but i read over your domain page and found an error in the linking to corp.com</p>
<p>7. Do you have other domains?</p>
<p>This is a generic page, so I don't know which domain you got here from. Here's a list of the names that get a lot of hits;</p>
<p>Corp.com<br />
Bar.com </p>
<p>corp.com and bar.com Hotlink is one hotlink not 2   if you click corp or bar it takes you to bar.   </p>
<p>Cole</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Adding capabilities to Mac OS X Lion Server by Mike O'Connor</title>
		<link>http://www.haven2.com/index.php/archives/adding-capabilities-to-mac-os-x-lion-server/comment-page-1#comment-39461</link>
		<dc:creator>Mike O'Connor</dc:creator>
		<pubDate>Wed, 21 Dec 2011 21:49:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/?p=816#comment-39461</guid>
		<description>Here&#039;s the link that I am thinking is this hack to add more names to the list -- http://www.bynari.net/support/users/kb.php?id=200049

It looks pretty straightforward, but I haven&#039;t tried it.</description>
		<content:encoded><![CDATA[<p>Here's the link that I am thinking is this hack to add more names to the list -- <a href="http://www.bynari.net/support/users/kb.php?id=200049" rel="nofollow">http://www.bynari.net/support/users/kb.php?id=200049</a></p>
<p>It looks pretty straightforward, but I haven't tried it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Adding capabilities to Mac OS X Lion Server by The Stig</title>
		<link>http://www.haven2.com/index.php/archives/adding-capabilities-to-mac-os-x-lion-server/comment-page-1#comment-39457</link>
		<dc:creator>The Stig</dc:creator>
		<pubDate>Wed, 21 Dec 2011 19:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/?p=816#comment-39457</guid>
		<description>Thanks Mike - this is a great list.  Regarding the limit of forwarding to a maximum of 4 users, you mention that there is a hack.  Do you have a link handy?  It appears that it woud be editing the correct Dovecot Sieve conf line to = 0 (unlimited) or however many addresses one needs.  I haven&#039;t found the right file yet, nor have I found any clear documentation on how to accomplish this.  Any help you can provide is appreciated.</description>
		<content:encoded><![CDATA[<p>Thanks Mike - this is a great list.  Regarding the limit of forwarding to a maximum of 4 users, you mention that there is a hack.  Do you have a link handy?  It appears that it woud be editing the correct Dovecot Sieve conf line to = 0 (unlimited) or however many addresses one needs.  I haven't found the right file yet, nor have I found any clear documentation on how to accomplish this.  Any help you can provide is appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Adding capabilities to Mac OS X Lion Server by Michael Fraase</title>
		<link>http://www.haven2.com/index.php/archives/adding-capabilities-to-mac-os-x-lion-server/comment-page-1#comment-39323</link>
		<dc:creator>Michael Fraase</dc:creator>
		<pubDate>Mon, 19 Dec 2011 00:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/?p=816#comment-39323</guid>
		<description>Mikey,

Here&#039;s a pointer to my own explorations:

http://www.farces.com/index.php/wiki/Category:Technology::Adventures_with_the_naked_Mac_Mini_Server/

And here&#039;s the best tip I can give you: Download Apple&#039;s Server Admin; it magically contains most of the configuration stuff that Apple stripped out for normal people:

http://support.apple.com/kb/DL1419</description>
		<content:encoded><![CDATA[<p>Mikey,</p>
<p>Here's a pointer to my own explorations:</p>
<p><a href="http://www.farces.com/index.php/wiki/Category:Technology::Adventures_with_the_naked_Mac_Mini_Server/" rel="nofollow">http://www.farces.com/index.php/wiki/Category:Technology::Adventures_with_the_naked_Mac_Mini_Server/</a></p>
<p>And here's the best tip I can give you: Download Apple's Server Admin; it magically contains most of the configuration stuff that Apple stripped out for normal people:</p>
<p><a href="http://support.apple.com/kb/DL1419" rel="nofollow">http://support.apple.com/kb/DL1419</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Comments/Questions by Mike O'Connor</title>
		<link>http://www.haven2.com/index.php/home/comment-page-1#comment-38011</link>
		<dc:creator>Mike O'Connor</dc:creator>
		<pubDate>Tue, 29 Nov 2011 03:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/index.php/home/#comment-38011</guid>
		<description>hi Derek,

are they really just using &quot;corp.com&quot; as the internal domain?  egad… it&#039;s no wonder their external users have slow logins.  first they hit my site, on a goofy port.  then, after that attempt takes a while to time out, the external user goes and looks up the internal address from the Windows server.  i would guess it takes at least 30 seconds for the first try to time out -- maybe more.  i&#039;d be happy to testify to your client.  :-)

if you want, we could do something with a sniffer on my end.  if you and i conspire on an exact time, i could fire up the sniffer and capture the login-attempt packets that are hitting my server.  you could tell me IP address and port ranges to filter for.  i could list out the hits.  maybe that would be enough...

another avenue towards &quot;proof&quot; (besides spending a quarter to buy them a clue) is this report from ICANN&#039;s SSAC (security and stability advisory committee) which provides a top-10 list of DNS queries by misconfigured servers.  &quot;corp&quot; is in that list.  not quite the same as your gang (since the worst offender is the string &quot;corp&quot; rather than &quot;corp.com&quot;) but close.  and i can tell you fersure that &quot;corp.com&quot; gets a **LOT** of traffic from folks like your gang that have pounded that into their configurations.  here&#039;s the link to the SSAC report

	http://www.icann.org/en/committees/security/sac045.pdf

i&#039;ll ping you by email so we can continue this discussion...</description>
		<content:encoded><![CDATA[<p>hi Derek,</p>
<p>are they really just using "corp.com" as the internal domain?  egad… it's no wonder their external users have slow logins.  first they hit my site, on a goofy port.  then, after that attempt takes a while to time out, the external user goes and looks up the internal address from the Windows server.  i would guess it takes at least 30 seconds for the first try to time out -- maybe more.  i'd be happy to testify to your client.  <img src='http://www.haven2.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>if you want, we could do something with a sniffer on my end.  if you and i conspire on an exact time, i could fire up the sniffer and capture the login-attempt packets that are hitting my server.  you could tell me IP address and port ranges to filter for.  i could list out the hits.  maybe that would be enough...</p>
<p>another avenue towards "proof" (besides spending a quarter to buy them a clue) is this report from ICANN's SSAC (security and stability advisory committee) which provides a top-10 list of DNS queries by misconfigured servers.  "corp" is in that list.  not quite the same as your gang (since the worst offender is the string "corp" rather than "corp.com") but close.  and i can tell you fersure that "corp.com" gets a **LOT** of traffic from folks like your gang that have pounded that into their configurations.  here's the link to the SSAC report</p>
<p>	<a href="http://www.icann.org/en/committees/security/sac045.pdf" rel="nofollow">http://www.icann.org/en/committees/security/sac045.pdf</a></p>
<p>i'll ping you by email so we can continue this discussion...</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Comments/Questions by Derek</title>
		<link>http://www.haven2.com/index.php/home/comment-page-1#comment-38009</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Tue, 29 Nov 2011 02:24:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.haven2.com/index.php/home/#comment-38009</guid>
		<description>Hi Mike.  I started working for a company that uses the internal domain name of corp.com.  I was researching some issues for them and stumbled across your site.  The issues have to do with slow login times for external users.  I&#039;m sure you see where this is going.  Anyway, I really want to prove to them their domain naming is an issue, especially when outside of the network.  As a contractor they want &quot;proof&quot;, however I&#039;m not allowed much access so I can&#039;t do anything very creative with the network, domain, or endpoints.  So, I was simply wondering if you ever take the site down for any kind of maintenance window.  I figured I could see how much of a difference it has when the wildcard is inactive.  Thanks!</description>
		<content:encoded><![CDATA[<p>Hi Mike.  I started working for a company that uses the internal domain name of corp.com.  I was researching some issues for them and stumbled across your site.  The issues have to do with slow login times for external users.  I'm sure you see where this is going.  Anyway, I really want to prove to them their domain naming is an issue, especially when outside of the network.  As a contractor they want "proof", however I'm not allowed much access so I can't do anything very creative with the network, domain, or endpoints.  So, I was simply wondering if you ever take the site down for any kind of maintenance window.  I figured I could see how much of a difference it has when the wildcard is inactive.  Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

