Skip to main content
Question

Use ARD instead of ssh

  • September 13, 2013
  • 9 replies
  • 0 views

Forum|alt.badge.img+3

I have a few hundred laptops already out with the students and im trying to remotely enroll them but i did not turn remote login on. I have remote management turned on because i use Apple Remote Desktop. Is there a way to change remote enrollment to use the ARD ports instead of the ssh ports? I really dont want to physically change the setting on each laptop in order to use this product.

Forum|alt.badge.img+7
  • Contributor
  • September 13, 2013

Why don't you use ARD to enable SSH (Remote Management) on the laptops. There's even a 'Send UNIX command' template in ARD that does just that.


RobertHammen
Forum|alt.badge.img+28
  • Esteemed Contributor
  • September 13, 2013

You may be able to use ARD to turn on SSH.

Not sure if one of these commands, run as root, will do the trick for you:

jamf startSSH

(if they're already enrolled in the JSS) or

systemsetup -setremotelogin on

I don't know if this will enable ssh for all users - something you probably want to control with greater detail.

To specify users to allow ssh access, follow the advice on dseditgroup mentioned in this blog link:

http://macadmincorner.com/securing-ssh/


Forum|alt.badge.img+31

SSH can also be enabled using Casper. You should be able to set up a policy that is scoped to machines that don't have remote login turned on, then use the following command to turn on SSH:

systemsetup -setremotelogin on

Forum|alt.badge.img+3
  • New Contributor
  • September 13, 2013

I tried running the systemsetup -setremotelogin on command via ard but i get the error

You need administrator access to run this tool... exiting!

if i run sudo systemsetup -setremotelogin

i get sudo: no tty present and no askpass program specified


Forum|alt.badge.img+7
  • Contributor
  • September 13, 2013

Are you using 'root' as the user in the Send UNIX command screen?


Forum|alt.badge.img+3
  • New Contributor
  • September 13, 2013

i am using the local admin account for the laptop


Forum|alt.badge.img+7
  • Contributor
  • September 13, 2013

I mean like this...

external image link


RobertHammen
Forum|alt.badge.img+28
  • Esteemed Contributor
  • September 13, 2013

^^^^exactly right. And you don't need to have the root login enabled for that to work (you generally shouldn't, as a rule).


Forum|alt.badge.img+3
  • New Contributor
  • September 13, 2013

you guys are the best :)


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings