This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mac OS - pre-configuring Autoupdate

We have quite a number of Macs (not surprising at a university) but no official Mac support. Nevertheless we offer Sophos for Macs (in a downloadable .zip archive).  

When Sophos is installed on a Mac on our network it connects to the management server from where it gets the update policy (the CIDs contain the correct mrinit.conf for RMS to work). Of course this does not work if the Mac is used at home. For windows PCs putting sauconf.xml placed in the appropriate directory does the trick. There are some articles in the knowledgebase but usually a Mac is required with which you can configure the CID (if I understand correctly). I believe no magic is actually involved and the configuration is stored somewhere in a .plist file (XML format). I suspect that the catalogues are involved and configcid.exe does not support a CID for OSX.

Or is there a "simple" way to pre-configure autoupdate (even if it's unsupported)? sau.plist looks suspicous  :smileywink:

Christian

:518


This thread was automatically locked due to age.
Parents

  • jelockwood wrote:

    I have now updated my installer package to include SAV 9.2.2 instead so as to be Yosemite compatible and it seems to work as desired in that it runs silently and does install it and the resulting install does have the pre-configured credentials to auto-update directly from Sophos. I have to directly update from Sophos because they killed of Sophos Update Manager and we have no Windows server to run Sophos Enterprise Console on and Sophos stubbornly refuse to port Enterprise Console to Linux/Unix or OS X.


    Updating from Sophos is typically more successful and reliable than what most folks can set up on their own. I would always encourage you to do it that way. This method of updating is also "friendly" (aka "works") with all HTTP cache products, whether its a commercial product like our web gateway or the open source Squid proxy.


    jelockwood wrote:

    After automatically installing SAV 9.2.2 as part of my DeployStudio / Munki build process I am finding that when I first login to a freshly minted Yosemite Mac I get a dialog box appearing from Keychain Migrator asking for the password for the Sophos keychain. I of course have no idea what that password would be as it is used and created by Sophos. I therefore have to click cancel and then the login proceeds and completes normally. Sophos seems to run ok after this and the message does not seem to reoccur on subsequent logins.

    Anyone else seeing this?


    I'm keen to hear more about this, its weird and unexpected. Definitely never seen it myself nor have we had it happen in our testing, but I can't say we would necessarily have the same endpoint configuration as you'd be running. Anything non-standard in your deployments that we should be trying?

    :54267
Reply

  • jelockwood wrote:

    I have now updated my installer package to include SAV 9.2.2 instead so as to be Yosemite compatible and it seems to work as desired in that it runs silently and does install it and the resulting install does have the pre-configured credentials to auto-update directly from Sophos. I have to directly update from Sophos because they killed of Sophos Update Manager and we have no Windows server to run Sophos Enterprise Console on and Sophos stubbornly refuse to port Enterprise Console to Linux/Unix or OS X.


    Updating from Sophos is typically more successful and reliable than what most folks can set up on their own. I would always encourage you to do it that way. This method of updating is also "friendly" (aka "works") with all HTTP cache products, whether its a commercial product like our web gateway or the open source Squid proxy.


    jelockwood wrote:

    After automatically installing SAV 9.2.2 as part of my DeployStudio / Munki build process I am finding that when I first login to a freshly minted Yosemite Mac I get a dialog box appearing from Keychain Migrator asking for the password for the Sophos keychain. I of course have no idea what that password would be as it is used and created by Sophos. I therefore have to click cancel and then the login proceeds and completes normally. Sophos seems to run ok after this and the message does not seem to reoccur on subsequent logins.

    Anyone else seeing this?


    I'm keen to hear more about this, its weird and unexpected. Definitely never seen it myself nor have we had it happen in our testing, but I can't say we would necessarily have the same endpoint configuration as you'd be running. Anything non-standard in your deployments that we should be trying?

    :54267
Children
No Data