<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Your Mac Guy (and more)</title>
	<atom:link href="https://yourmacguy.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://yourmacguy.wordpress.com</link>
	<description>mac and linux tips/tricks/tools</description>
	<lastBuildDate>Mon, 20 May 2013 20:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='yourmacguy.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>https://secure.gravatar.com/blavatar/14b0d1f0ddab8a83fe474007561342d8?s=96&#038;d=https%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Your Mac Guy (and more)</title>
		<link>https://yourmacguy.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="https://yourmacguy.wordpress.com/osd.xml" title="Your Mac Guy (and more)" />
	<atom:link rel='hub' href='https://yourmacguy.wordpress.com/?pushpress=hub'/>
		<item>
		<title>ADPassMon updated to 1.8</title>
		<link>https://yourmacguy.wordpress.com/2012/11/28/adpassmon-updated-to-1-8/</link>
		<comments>https://yourmacguy.wordpress.com/2012/11/28/adpassmon-updated-to-1-8/#comments</comments>
		<pubDate>Wed, 28 Nov 2012 19:55:09 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=782</guid>
		<description><![CDATA[This version brings official OS X 10.8 compatibility and uses Notification Center instead of Growl for alerts when running on Mountain Lion. Download it here.<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=782&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img class="size-full wp-image-783 alignright" title="ml-logo" alt="" src="http://yourmacguy.files.wordpress.com/2012/11/ml-logo.png?w=630"   /></p>
<p>This version brings official OS X 10.8 compatibility and uses Notification Center instead of Growl for alerts when running on Mountain Lion.</p>
<p>Download it <a title="Download ADPassMon v1.8" href="https://dl.dropbox.com/u/3967964/ADPassMon.v1.8.dmg">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/782/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=782&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/11/28/adpassmon-updated-to-1-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>

		<media:content url="http://yourmacguy.files.wordpress.com/2012/11/ml-logo.png" medium="image">
			<media:title type="html">ml-logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Update NFS automounts from the terminal</title>
		<link>https://yourmacguy.wordpress.com/2012/10/02/update-nfs-terminal/</link>
		<comments>https://yourmacguy.wordpress.com/2012/10/02/update-nfs-terminal/#comments</comments>
		<pubDate>Tue, 02 Oct 2012 21:04:14 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[mac os x]]></category>
		<category><![CDATA[Terminal tricks]]></category>
		<category><![CDATA[10.6]]></category>
		<category><![CDATA[10.7]]></category>
		<category><![CDATA[10.8]]></category>
		<category><![CDATA[automount]]></category>
		<category><![CDATA[mountain lion]]></category>
		<category><![CDATA[nfs]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=769</guid>
		<description><![CDATA[If you&#8217;ve used Disk Utility1 to set up automounts &#8212; or you recently upgraded to Mountain Lion and found that the GUI for editing NFS mounts has disappeared &#8212; and find yourself needing to quickly update the records, this tip is for you. We moved a bunch of NFS shares from one server to another over [&#8230;]<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=769&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>If you&#8217;ve used Disk Utility<sup><a href="#note1">1</a></sup> to set up automounts &#8212; or you recently upgraded to Mountain Lion and found that the GUI for editing NFS mounts has disappeared &#8212; and find yourself needing to quickly update the records, this tip is for you.</p>
<p>We moved a bunch of NFS shares from one server to another over the weekend and needed to update the mount records on all clients that aren&#8217;t using our LDAP-based automount records. A handful of Macs with manually-configured NFS shares had lost access to these relocated shares. Disk Utility stores its mount records as (non-binary) plists in  <strong>/var/db/dslocal/nodes/Default/mounts</strong>. One of the lines in a mount plist contains the <strong>server:/path/to/share</strong> line for that automount.</p>
<p>To update the mount record, do the following using root privileges:</p>
<ol>
<li>Find the plist that contains the path you need to update in <strong>/var/db/dslocal/nodes/Default/mounts</strong>.</li>
<li>Use your favorite text editing tool to update the path record, or replace the entire plist with one that contains the updated record.</li>
<li>Run <strong>automount -vc</strong> to flush the cache and read in the updated information.</li>
</ol>
<p>That&#8217;s all there is to it. I leave it as an exercise for the reader to combine all the steps into a deployable, scripted solution.</p>
<p><a><br />
_____<br />
<small></small></a>1. If you&#8217;re using OS X 10.5, it&#8217;s in Directory Utility.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/769/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=769&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/10/02/update-nfs-terminal/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon updated to 1.7</title>
		<link>https://yourmacguy.wordpress.com/2012/07/11/adpassmon-updated-to-1-7-2/</link>
		<comments>https://yourmacguy.wordpress.com/2012/07/11/adpassmon-updated-to-1-7-2/#comments</comments>
		<pubDate>Wed, 11 Jul 2012 13:46:36 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=763</guid>
		<description><![CDATA[Bug fix: The Change Password dialog now opens in the foreground. Download it here.<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=763&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><strong>Bug fix:</strong> The Change Password dialog now opens in the foreground.</p>
<p>Download it <a title="ADPassMon.v.1.7" href="https://dl.dropbox.com/u/3967964/ADPassMon.v1.7.dmg">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/763/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/763/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=763&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/07/11/adpassmon-updated-to-1-7-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>Automount NFS in OS X</title>
		<link>https://yourmacguy.wordpress.com/2012/06/29/osx-automount/</link>
		<comments>https://yourmacguy.wordpress.com/2012/06/29/osx-automount/#comments</comments>
		<pubDate>Fri, 29 Jun 2012 15:00:02 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[mac os x]]></category>
		<category><![CDATA[autofs]]></category>
		<category><![CDATA[automount]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[nfs]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=735</guid>
		<description><![CDATA[I work in a mixed Mac/Windows/Linux environment. The majority of our fileshares are located on Isilon gear and are accessible over SMB with AD authentication, and over NFS with LDAP authentication. Our Macs bind to AD and therefore use SMB to access fileshares. As the size of the scientific datasets people use grow, the (lack [&#8230;]<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=735&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I work in a mixed Mac/Windows/Linux environment. The majority of our fileshares are located on <a href="http://www.isilon.com/onefs-operating-system">Isilon</a> gear and are accessible over SMB with AD authentication, and over NFS with LDAP authentication. Our Macs bind to AD and therefore use SMB to access fileshares. As the size of the scientific datasets people use grow, the (lack of) performance of SMB in Mac OS X becomes more of an issue &#8212; especially for people who know they can get far better performance in Windows and Linux. To remedy this, with the help of my colleague and Mac admin, <a href="http://derflounder.wordpress.com/">Rich Trouton</a>, we&#8217;ve started to migrate certain Mac users away from AD and SMB to LDAP and NFS. Because our Mac users have mobile accounts with local homes, the move requires a bit of finagling, which is why <a href="http://derflounder.wordpress.com/2012/03/16/interactive-local-user-ldap-mobile-account-migration-script/">Rich scripted the process</a>.</p>
<p>Once a Mac user&#8217;s account has been migrated to LDAP, s/he can use NFS URLs in the Finder&#8217;s <strong>Connect to Server</strong> window and will see vastly superior performance to the previous SMB connections. The more Macs we convert to LDAP/NFS, the more active connections we&#8217;ll have to our fileservers. At a certain point, this will become a problem. Fortunately, there&#8217;s a way around this that all our linux computers already use: <a href="http://www.linux-consulting.com/Amd_AutoFS/autofs-3.html#ss3.1">autofs</a>. Autofs will automatically mount fileshares on an as-needed basis and will automatically disconnect fileshares after an idle timeout period (which defaults to one hour). Another benefit of autofs is that users no longer have to mount shares manually. Simply by navigating to where the share is <em>supposed to be</em> will mount it there. Automount is clearly the best solution going forward.</p>
<p>My primary goals for this NFS automounting solution was to <a href="#package">make it easy to manage and update</a> — we sometimes add and remove fileshares — and to have the Macs mount fileshares at exactly the same paths as in Linux, inside a root-level directory called &#8216;groups&#8217;. Because of a peculiarity in OS X Lion&#8217;s Finder (<a href="#notldap">that I&#8217;ll discuss later</a>), this goal precluded the use of the automount maps that our linux hosts get from LDAP. My solution (which works with OS 10.6 through 10.8) adds entries to <strong>/etc/auto_master</strong> that reference files in a new <strong>/etc/automounts</strong> directory.</p>
<h2>Example Scenario</h2>
<p>Let&#8217;s say my Isilon cluster is called <strong>shares.example.com</strong> and it is exporting a number of NFS shares with root paths beginning with <strong>/ifs/groups/foo</strong>, <strong>/ifs/groups/bar</strong>, and <strong>/ifs/groups/baz</strong>. Each of these directories contains at least two subfolders which are the actual shares. I want these shares to mount inside <strong>/groups/foo</strong>, <strong>/groups/bar</strong>, and <strong>/groups/baz</strong>. To do this, I need to create three files inside a new <strong>/etc/automounts</strong> directory called <strong>foo</strong>, <strong>bar</strong>, and <strong>baz</strong> containing the respective automount maps. Because I&#8217;m working outside the user space, I&#8217;ll need root/admin privileges.</p>
<p>Here&#8217;s what /etc/automounts/foo looks like:</p>
<pre>*        -fstype=nfs,rw,bg,hard,intr,tcp share.example.com:/ifs/groups/foo/&amp;</pre>
<p>The asterisk at the beginning and the ampersand at the end of the line tell automount to mount any shares it finds inside /ifs/groups/foo with the same name as the share. This saves me from having to specify each share individually. (The mount options are beyond the scope of this post, but <a href="http://linux.die.net/man/5/nfs">go here if you want to learn more about them</a>.) The other two mounts follow this same pattern. You can, of course, specify each share individually. These mount files can have any number of lines in them.</p>
<p>When all the mount files are written, I need to add one line per file to my <strong>/etc/auto_master</strong> file. It ends up looking like this:</p>
<pre>#
# Automounter master map
#
+master # Use directory service
/net -hosts -nobrowse,hidefromfinder,nosuid
/home home -nobrowse,hidefromfinder
/Network/Servers -fstab
/- -static
## everything above this line is in the default auto_master file ##
/groups/foo /etc/automounts/foo
/groups/bar /etc/automounts/bar
/groups/baz /etc/automounts/baz</pre>
<p>Looks pretty straightforward, right? After these modifications are in place, I check to make sure all files are root:wheel owned, the automounts directory has rwxr-xr-x (755) permissions and /etc/auto_master and all files within /etc/automounts have rw-r&#8211;r&#8211; (644) permissions. Now I need to restart the automounter so it sees the new mount maps:</p>
<pre>sudo automount -vc</pre>
<p>When this command runs, it should output all the new mounts it has created. The first three lines are from Apple&#8217;s default mounts:</p>
<pre>automount: /net updated
automount: /home updated
automount: /Network/Servers updated
automount: /groups/foo mounted
automount: /groups/bar mounted
automount: /groups/baz mounted
automount: no unmounts</pre>
<p>Now, even though it says &#8220;mounted&#8221;, nothing has actually been mounted. If you look in the Finder, you should see that autmount has created the mount  points, but nothing else. This is an important concept to understand. A share will not actually mount until you <strong>traverse</strong> its mount point. This is confusing for anyone who has not wrapped their head around autofs — and I&#8217;m staring in the general direction of most Mac users, here. For example, let&#8217;s say you want to get to /groups/foo/images. If you look inside /groups/foo in the Finder or the Terminal, you will see an empty directory. To go that next step, you&#8217;ll need to either use &#8220;Go to Folder&#8221; and specify &#8220;/groups/foo/images&#8221; or use the terminal and cd into that directory.</p>
<p>One last thing to mention. You will probably wish to disable the creation of <a href="http://en.wikipedia.org/wiki/.DS_Store">.DS_Store</a> files on network volumes when using automounts. The Finder has a bad habit of leaving these files open, so your automounted shares will not unmount after set idle times like they&#8217;re supposed to. To keep your Mac from writing .DS_Store files to network drives, run the following defaults command in the terminal. This is a per-user setting.</p>
<pre>defaults write com.apple.desktopservices DSDontWriteNetworkStores true</pre>
<p><a name="package"></a></p>
<h2>Deploying this solution</h2>
<p>As I mentioned earlier, because we add and remove new shares semi-regularly, I needed this solution to be manageable. If you&#8217;re already using configuration management tools in your Mac environment — be it <a href="http://www.jamfsoftware.com/products/casper-suite/">Casper</a>, <a href="http://projects.puppetlabs.com/projects/puppet/wiki/Puppet_Mac_OSX">Puppet</a>, or anything else — you&#8217;re probably already familiar with the best way to deploy and manage a small collection of files. My colleague Rich <a href="http://derflounder.wordpress.com/2012/06/29/deploying-nfs-automounts-for-macs-via-installer-package/">just wrote up</a> how to wrap all this into a package that you can deploy with your tool of choice. Any time we add or remove a share, we can push out a new package with the changes and the packages postinstall script will reload automount. The reload process won&#8217;t affect any active mounts so we can push the package out at any time.</p>
<p><a name="notldap"></a></p>
<h2>Appendix: Why not use LDAP?</h2>
<p>Because the Finder (at least since 10.7) will rename mount points to match the filename that contains the autofs mapping. Our LDAP server&#8217;s maps are named with a format of <em>auto.groups.foo</em>. As soon as you go into a share inside /groups/foo, e.g. /groups/foo/images, the Finder renames the foo directory to auto.groups.foo. Directory names viewed from the Terminal are unaffected.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/735/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/735/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=735&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/06/29/osx-automount/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon updated to 1.6</title>
		<link>https://yourmacguy.wordpress.com/2012/04/09/adpassmon-updated-to-1-6/</link>
		<comments>https://yourmacguy.wordpress.com/2012/04/09/adpassmon-updated-to-1-6/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 03:28:33 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=731</guid>
		<description><![CDATA[New feature: &#8220;Launch Ticket Viewer&#8221; menu item, launches Ticket Viewer.app. Download it here.<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=731&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><strong>New feature:</strong> &#8220;Launch Ticket Viewer&#8221; menu item, launches Ticket Viewer.app.</p>
<p>Download it <a title="ADPassMon1.6" href="http://dl.dropbox.com/u/3967964/ADPassMon.v1.6.dmg">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/731/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=731&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/04/09/adpassmon-updated-to-1-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!</title>
		<link>https://yourmacguy.wordpress.com/2012/02/21/edit-known_hosts/</link>
		<comments>https://yourmacguy.wordpress.com/2012/02/21/edit-known_hosts/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 22:33:05 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[bash]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Scripting]]></category>
		<category><![CDATA[bashrc]]></category>
		<category><![CDATA[function]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=715</guid>
		<description><![CDATA[@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed. The fingerprint for the RSA key sent by the remote host is 00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff. Please [&#8230;]<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=715&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<pre>@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
00:11:22:33:44:55:66:77:88:99:aa:bb:cc:dd:ee:ff.
Please contact your system administrator.
Add correct host key in /home/username/.ssh/known_hosts to get rid of this message.
Offending RSA key in /home/username/.ssh/known_hosts:42
RSA host key for 10.1.2.3 has changed and you have requested strict checking.
Host key verification failed.</pre>
<p>If you use ssh &#8212; if you&#8217;re reading this blog, you likely count yourself as a member of that group &#8212; you&#8217;ve seen this warning. If you bring up and take down vms regularly, or replace servers regularly, or use dhcp on your network with short lease times, you might see this warning more than others. Regardless of how or when you&#8217;ve seen the warning, you probably find it annoying. &#8220;No, computer, I&#8217;m not being hacked. A different host has this IP now. Just let me in already, ok?&#8221; At this point, you open the known_hosts file in your editor of choice, find the offending line, delete the line, save the file, and try your ssh command again. Tedious, right?</p>
<p>We can all agree that simply turning off this warning is not the best idea, so how can we deal with it efficiently? (HINT: check this posts categories.) That&#8217;s right, we script it. We don&#8217;t need any more than a simple one-liner, and the best place to keep your one-liner scripts is in your .bashrc file (or the shell of your choice&#8217;s rc file).</p>
<p>Do you see how the error kindly tells you which line of the known_hosts file is the offender? This makes our job extremely easy. Both <strong>sed</strong> and <strong>perl</strong> can easily delete a given line from a file. <span style="color:#0000ff;">(NOTE: Mac users will need to use perl, since BSD version of sed does not include the functionality shown here.)</span> Both of the following commands will delete line 42 from the file.</p>
<pre>sed -i '42 d' ~/.ssh/known_hosts</pre>
<pre>perl -i -ne 'print unless 42 .. 42" ~/.ssh/known_hosts</pre>
<p>These are nice, but we need to wrap the command in a function that takes the line number as an argument. Let&#8217;s call the function <strong>rmhost</strong>.</p>
<pre>rmhost () { sed -i "$1 d" ~/.ssh/known_hosts; }</pre>
<pre>rmhost () { perl -i -ne "print unless $1 .. $1" ~/.ssh/known_hosts; } # for Macs</pre>
<p>And there we have it. Put your command in your .bashrc, source it (i.e. load the changes by running &#8216;source ~/.bashrc&#8217;), and the next time you see the above warning (and you know the reason you&#8217;re getting it), just type <strong>rmhost [line #]</strong> and you&#8217;re good to go.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/715/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=715&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/02/21/edit-known_hosts/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon updated to 1.5</title>
		<link>https://yourmacguy.wordpress.com/2012/02/13/adpassmon-updated-to-1-5/</link>
		<comments>https://yourmacguy.wordpress.com/2012/02/13/adpassmon-updated-to-1-5/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 22:13:27 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=711</guid>
		<description><![CDATA[ADPassMon now works with multi-domain AD forests. Download version 1.5 here.<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=711&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>ADPassMon now works with multi-domain AD forests.</p>
<p><a title="Download ADPassMon 1.5" href="http://dl.dropbox.com/u/3967964/ADPassMon.v1.5.dmg">Download version 1.5 here.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/711/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/711/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=711&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2012/02/13/adpassmon-updated-to-1-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon updated to 1.4</title>
		<link>https://yourmacguy.wordpress.com/2011/11/03/adpassmon-updated-to-1-4/</link>
		<comments>https://yourmacguy.wordpress.com/2011/11/03/adpassmon-updated-to-1-4/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 19:44:33 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=708</guid>
		<description><![CDATA[This update makes ADPassMon compatible with Growl 1.3. If you&#8217;re still using an older version of Growl, you do not need this update, but it is also compatible with older versions of Growl. Download version 1.4 here. &#160;<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=708&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This update makes ADPassMon compatible with Growl 1.3. If you&#8217;re still using an older version of Growl, you do not need this update, but it is also compatible with older versions of Growl.</p>
<p><a title="ADPassMon v1.4" href="http://dl.dropbox.com/u/3967964/ADPassMon.v1.4.dmg">Download version 1.4 here.</a></p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/708/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/708/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=708&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2011/11/03/adpassmon-updated-to-1-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon updated to 1.3</title>
		<link>https://yourmacguy.wordpress.com/2011/10/12/adpassmon-updated-to-1-3/</link>
		<comments>https://yourmacguy.wordpress.com/2011/10/12/adpassmon-updated-to-1-3/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 19:36:06 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=701</guid>
		<description><![CDATA[This minor update fixes an error that affects Macs with only one DNS server configured. Download ADPassMon v1.3<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=701&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This minor update fixes an error that affects Macs with only one DNS server configured.</p>
<p><a title="Download ADPassMon v1.3" href="http://dl.dropbox.com/u/3967964/ADPassMon.v1.3.dmg">Download ADPassMon v1.3</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/701/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/701/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=701&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2011/10/12/adpassmon-updated-to-1-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>
	</item>
		<item>
		<title>ADPassMon and FileVault 2</title>
		<link>https://yourmacguy.wordpress.com/2011/09/12/adpassmon-filevault2/</link>
		<comments>https://yourmacguy.wordpress.com/2011/09/12/adpassmon-filevault2/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 18:13:56 +0000</pubDate>
		<dc:creator>pmbuko</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://yourmacguy.wordpress.com/?p=692</guid>
		<description><![CDATA[+ ADPassMon user Cesar Gonzalez sent me a nice note to let me know that Apple engineers suggested using ADPassMon to work around a problem he encountered after deploying FileVault 2. Due to the EFI boot authentication passthrough, his users are no longer notified of the pending password expirations at the login screen. Since ADPassMon runs [&#8230;]<img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=692&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><img style="vertical-align:middle;" title="lock-icon_sm" src="http://yourmacguy.files.wordpress.com/2011/09/lock-icon_sm.png?w=42&#038;h=64" alt="adpassmon icon" width="42" height="64" /><strong> + </strong><img style="vertical-align:middle;" title="features_filevault2_icon" src="http://yourmacguy.files.wordpress.com/2011/09/features_filevault2_icon.png?w=64&#038;h=64" alt="filevault2 icon" width="64" height="64" /></p>
<p>ADPassMon user Cesar Gonzalez sent me a nice note to let me know that Apple engineers suggested using ADPassMon to work around a problem he encountered after deploying FileVault 2. Due to the EFI boot authentication passthrough, his users are no longer notified of the pending password expirations at the login screen. Since ADPassMon runs after the login process, it works whether FileVault 2 is enabled or not.</p>
<p>Adding to ADPassMon&#8217;s feature list without any additional work seems like a big win to me. :) Thanks again, Cesar!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/yourmacguy.wordpress.com/692/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/yourmacguy.wordpress.com/692/" /></a> <img alt="" border="0" src="https://stats.wordpress.com/b.gif?host=yourmacguy.wordpress.com&#038;blog=4297208&#038;post=692&#038;subd=yourmacguy&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://yourmacguy.wordpress.com/2011/09/12/adpassmon-filevault2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="https://0.gravatar.com/avatar/61f2957855ade40d46a4549a3579bedf?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">pmbuko</media:title>
		</media:content>

		<media:content url="http://yourmacguy.files.wordpress.com/2011/09/lock-icon_sm.png" medium="image">
			<media:title type="html">lock-icon_sm</media:title>
		</media:content>

		<media:content url="http://yourmacguy.files.wordpress.com/2011/09/features_filevault2_icon.png" medium="image">
			<media:title type="html">features_filevault2_icon</media:title>
		</media:content>
	</item>
	</channel>
</rss>
