<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tobi&#039;s Tipps</title>
	<atom:link href="https://tobir.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://tobir.org/</link>
	<description>Technik &#38; Tools</description>
	<lastBuildDate>Fri, 14 Nov 2025 15:00:43 +0000</lastBuildDate>
	<language>de</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Heruntergeladenes Update für macOS kann nicht installiert werden, da Speicherplatz fehlt</title>
		<link>https://tobir.org/heruntergeladenes-update-fuer-macos-kann-nicht-installiert-werden-da-speicherplatz-fehlt/</link>
					<comments>https://tobir.org/heruntergeladenes-update-fuer-macos-kann-nicht-installiert-werden-da-speicherplatz-fehlt/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Fri, 14 Nov 2025 15:00:42 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[macOS]]></category>
		<category><![CDATA[safe mode]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=537</guid>

					<description><![CDATA[<p>Wenn Updates wegen zu wenig freiem Speicherplatz fehlschlagen hilft es, den Mac einmal im sicheren Modus zu starten.</p>
<p>Der Beitrag <a href="https://tobir.org/heruntergeladenes-update-fuer-macos-kann-nicht-installiert-werden-da-speicherplatz-fehlt/">Heruntergeladenes Update für macOS kann nicht installiert werden, da Speicherplatz fehlt</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Es kann vorkommen, dass in macOS zwar die automatische Installation von Updates aktiviert ist, es aber wegen zu wenig Platz auf der Festplatte / SSD schon beim Download scheitert. Selbst wenn der Download gelingt, kann trotzdem zu wenig freier Speicherplatz da sein, um das Update zu installieren.</p>



<p class="wp-block-paragraph">Wie wird man das halb heruntergeladene oder hängende Update wieder los und gewinnt den Speicherplatz zurück? Früher wäre händisches Aufräumen in <br><em>/Library/Updates</em> nötig gewesen und dabei kann so einiges schiefgehen.</p>



<p class="wp-block-paragraph">Der Mac räumt diese Dateien aber automatisch auf, wenn man ihn im <em>sicheren Modus </em>startet. Windows Admins kommt der abgesicherte Modus bestimmt bekannt vor, der Mac hat sowas auch.</p>



<p class="wp-block-paragraph">Apple beschreibt hier, wie man den Mac im sicheren Modus startet:<br><a href="https://support.apple.com/de-de/guide/mac-help/mh21245/mac">https://support.apple.com/de-de/guide/mac-help/mh21245/mac</a></p>



<p class="wp-block-paragraph">Nachdem man sich im sicheren Modus am Mac angemeldet hat, sind die anstehenden macOS Updates gelöscht und man kann den Mac dann wieder normal starten.</p>



<p class="wp-block-paragraph"></p>
<p>Der Beitrag <a href="https://tobir.org/heruntergeladenes-update-fuer-macos-kann-nicht-installiert-werden-da-speicherplatz-fehlt/">Heruntergeladenes Update für macOS kann nicht installiert werden, da Speicherplatz fehlt</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/heruntergeladenes-update-fuer-macos-kann-nicht-installiert-werden-da-speicherplatz-fehlt/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>No AI content / kein KI-generierter Inhalt</title>
		<link>https://tobir.org/no-ai-content-kein-ki-generierter-inhalt/</link>
					<comments>https://tobir.org/no-ai-content-kein-ki-generierter-inhalt/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Tue, 02 Sep 2025 09:44:00 +0000</pubDate>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[KI]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=533</guid>

					<description><![CDATA[<p>All here published content is created by humans, without any use of LLMs or AI in general. This disclaimer is inspired by Howard Oakley&#8217;s article. Alles hier geschriebene wurde von Menschen erstellt, vollkommen ohne die Nutzung von LLMs oder KI im Allgemeinen. Diese Stellungnahme wurde durch Howard Oakleys Artikel inspriert.</p>
<p>Der Beitrag <a href="https://tobir.org/no-ai-content-kein-ki-generierter-inhalt/">No AI content / kein KI-generierter Inhalt</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">All here published content is created by humans, without any use of LLMs or AI in general. This disclaimer is inspired by <a href="https://eclecticlight.co/2025/07/27/last-week-on-my-mac-%F0%9F%A6%89-no-ai-content">Howard Oakley&#8217;s article</a>.</p>



<p class="wp-block-paragraph">Alles hier geschriebene wurde von Menschen erstellt, vollkommen ohne die Nutzung von LLMs oder KI im Allgemeinen. Diese Stellungnahme wurde durch <a href="https://eclecticlight.co/2025/07/27/last-week-on-my-mac-%F0%9F%A6%89-no-ai-content">Howard Oakleys Artikel</a> inspriert.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
<p>Der Beitrag <a href="https://tobir.org/no-ai-content-kein-ki-generierter-inhalt/">No AI content / kein KI-generierter Inhalt</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/no-ai-content-kein-ki-generierter-inhalt/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Part 2 of the ACME certificate workflow</title>
		<link>https://tobir.org/part-2-of-the-acme-certificate-workflow/</link>
					<comments>https://tobir.org/part-2-of-the-acme-certificate-workflow/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Fri, 01 Aug 2025 08:36:38 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[ACME]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=525</guid>

					<description><![CDATA[<p>Further refinement of the ACME workflow, configuring the renewal of certificates.</p>
<p>Der Beitrag <a href="https://tobir.org/part-2-of-the-acme-certificate-workflow/">Part 2 of the ACME certificate workflow</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">See <a href="https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/">part 1</a>, if you want general information on how to implement 802.1X device certificates with Jamf via the ACME protocol.</p>



<p class="wp-block-paragraph">Our whole workflow does, what it should do, right? Not quite, the renewal process of the certificates is not configurable. But Jamf did just that with the <a href="https://learn.jamf.com/en-US/bundle/jamf-pro-release-notes-11.19.0/page/New_Features_and_Enhancements.html">release of 11.19.0</a> of Jamf Pro.</p>



<h2 class="wp-block-heading">Renewal of certificates</h2>



<p class="wp-block-paragraph">Now, it is possible to set a renewal date relative to the expiry date! </p>



<p class="wp-block-paragraph">As our certificates are valid for 90 days, we chose 30 days until expiry as a good starting point. It is long enough, so that vacations or business trips don&#8217;t end with an expired certificate.</p>



<figure class="wp-block-image size-large"><a href="https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56.jpg"><img fetchpriority="high" decoding="async" width="1024" height="79" src="https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56-1024x79.jpg" alt="" class="wp-image-526" srcset="https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56-1024x79.jpg 1024w, https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56-300x23.jpg 300w, https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56-768x59.jpg 768w, https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56-1536x119.jpg 1536w, https://tobir.org/wp-content/uploads/2025/08/Bildschirmfoto-2025-08-01-um-09.38.56.jpg 1577w" sizes="(max-width: 1024px) 100vw, 1024px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">Change the value from <em>never</em> to the desired interval e.g. <em>30 days</em>.</p>



<h2 class="wp-block-heading">Further thoughts about the whole ACME workflow</h2>



<ul class="wp-block-list">
<li>A revocation procedure would be nice. This might be useful, when a device gets compromised or stolen. Sadly, step-ca does not support a certificate-revocation-list, but certificates can be revoked manually. <a href="https://smallstep.com/docs/step-ca/revocation/">See here</a> for further details.</li>



<li>Instead of deploying a completely new root-ca, maybe an existing one can be used as a trust anchor and our intermediate-ca can be signed by that? There is also <a href="https://smallstep.com/docs/tutorials/intermediate-ca-new-ca/">documentation available</a> for that case.</li>



<li>Our iPads can be managed the same way, just a <a href="https://github.com/jedda/step-posture-connector/wiki/Setup-Guide#adding-webhooks-to-your-step-ca-acme-provisioner">different webhook</a> is needed.</li>



<li>What about signing certificates for Android or Windows devices? They can&#8217;t use the device attestation protocol with Apple&#8217;s servers. Android devices may come into Jamf one day, our active directory for the Windows devices could be deprecated, once Microsoft chose to do that.</li>
</ul>



<p class="wp-block-paragraph"></p>
<p>Der Beitrag <a href="https://tobir.org/part-2-of-the-acme-certificate-workflow/">Part 2 of the ACME certificate workflow</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/part-2-of-the-acme-certificate-workflow/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to get device certificates on Jamf-managed Macs via ACME with step-ca and use it to join a 802.1X secured network</title>
		<link>https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/</link>
					<comments>https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Fri, 25 Jul 2025 15:55:19 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[802.1X]]></category>
		<category><![CDATA[ACME]]></category>
		<category><![CDATA[Jamf Pro]]></category>
		<category><![CDATA[PKI]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=491</guid>

					<description><![CDATA[<p>At work, our Windows computers are bound to AD, they use the AD-integrated PKI to generate device certificates. These certificates are then utilized to get 802.1X authenticated network access, both wired and Wi-Fi. Our Macs are not bound to AD, but managed with Jamf Pro as our MDM system. In order to also bring the &#8230; <a href="https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/" class="more-link"><span class="screen-reader-text">How to get device certificates on Jamf-managed Macs via ACME with step-ca and use it to join a 802.1X secured network</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/">How to get device certificates on Jamf-managed Macs via ACME with step-ca and use it to join a 802.1X secured network</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">At work, our Windows computers are bound to AD, they use the AD-integrated PKI to generate device certificates. These certificates are then utilized to get 802.1X authenticated network access, both wired and Wi-Fi.</p>



<p class="wp-block-paragraph">Our Macs are not bound to AD, but managed with Jamf Pro as our MDM system. In order to also bring the Macs into the network, we had to prepare a few things:</p>



<ol class="wp-block-list">
<li>Set up a separate certificate authority (CA), at best on premise and also without additional costs.</li>



<li>Chose a protocol for certificate creation, SCEP or ACME.</li>



<li>Build a configuration profile for Jamf, so the Macs get certificates and also renewals.</li>



<li>Integrate our new CA into our network tool (Cisco ISE)</li>
</ol>



<p class="wp-block-paragraph">Our options for free, open source and locally deployable CA&#8217;s are quite limited, also the support for <a href="https://support.apple.com/en-au/guide/deployment/dep28afbde6a/web">Managed-Device-Attestation</a> (MDA) from Apple was desired. This led us to smallstep&#8217;s <a href="https://smallstep.com/docs/step-ca/">step-ca</a> in conjunction with the <a href="https://github.com/jedda/step-posture-connector">Step Posture Connector</a> and ACME as the protocol that supports MDA. </p>



<h2 class="wp-block-heading">1. <strong>The CA</strong></h2>



<p class="wp-block-paragraph">Let&#8217;s start with the setup of step-ca on an Ubuntu server. The firewall has to allow Port 443 for all the <a href="https://learn.jamf.com/en-US/bundle/technical-articles/page/Permitting_InboundOutbound_Traffic_with_Jamf_Cloud.html">jamf servers</a>, and for the company network, so the Macs can also reach it. Additional documentation from smallstep is available here:</p>



<p class="wp-block-paragraph"><a href="https://smallstep.com/docs/step-ca/installation/#debianubuntu">https://smallstep.com/docs/step-ca/installation/#debianubuntu</a><br><a href="https://smallstep.com/docs/step-ca/acme-basics/">https://smallstep.com/docs/step-ca/acme-basics/</a><br><a href="https://smallstep.com/docs/step-ca/provisioners/#acme">https://smallstep.com/docs/step-ca/provisioners/#acme</a><br><a href="https://smallstep.com/blog/private-acme-server/">https://smallstep.com/blog/private-acme-server/</a></p>



<pre class="wp-block-code"><code># create the CA
step ca init</code></pre>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-small-font-size wp-block-paragraph">&#8230;<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Deployment Type: Standalone<br>What would you like to name your new PKI?<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> (e.g. Smallstep): OurTestCA<br>What DNS names or IP addresses will clients use to reach your CA?<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> (e.g. ca.example.com[,10.1.2.3,etc.]): catest.domain.name<br>What IP and port will your new CA bind to? (:443 will bind to 0.0.0.0:443)<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> (e.g. :443 or 127.0.0.1:443): :443<br>What would you like to name the CA&#8217;s first provisioner?<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> (e.g. you@smallstep.com): your.address@domain.name<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> [leave empty and we&#8217;ll generate one]:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Password: ThisIsATopSecretRootPasswordExample</p>



<p class="has-small-font-size wp-block-paragraph">Generating root certificate… done!<br>Generating intermediate certificate… done!</p>
</blockquote>



<p class="wp-block-paragraph">Take good care of the newly created root password!</p>



<p class="wp-block-paragraph">Now, let&#8217;s move the CA to /etc/step-ca and create a daemon to start it automatically. See <a href="https://smallstep.com/docs/step-ca/certificate-authority-server-production/index.html#running-step-ca-as-a-daemon">this guide</a> for it. The root password should now be in /etc/step-ca/password.txt</p>



<p class="wp-block-paragraph">Best practice for additional security is to change the password for the intermediate certificate, as it is used to sign our device certificates, and it then differs from your root certificates&#8216; password. See also <a href="https://smallstep.com/docs/step-ca/certificate-authority-server-production/index.html#use-strong-passwords-and-store-them-well">this guide</a>.</p>



<pre class="wp-block-code"><code>step crypto change-pass $(step path)/secrets/intermediate_ca_key</code></pre>



<p class="wp-block-paragraph">Now, we can configure the step-ca to use ACME and also to use MDA. We have to add a provisioner:</p>



<pre class="wp-block-code"><code>step ca provisioner add acme-da --type ACME --challenge device-attest-01 
--attestation-format apple</code></pre>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-small-font-size wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> CA Configuration: /etc/step-ca/config/ca.json</p>



<p class="has-small-font-size wp-block-paragraph">Success! Your <code>step-ca</code> config has been updated. To pick up the new configuration SIGHUP (kill -1 ) or restart the step-ca process.</p>
</blockquote>



<p class="wp-block-paragraph">Optionally, you can install the new CA certificates on the Ubuntu server via:</p>



<pre class="wp-block-code"><code>step certificate install $(step path)/certs/root_ca.crt</code></pre>



<p class="wp-block-paragraph">They can be also downloaded from the server:</p>



<p class="wp-block-paragraph">https://catest.domain.name/roots.pem<br>https://catest.domain.name/intermediates.pem</p>



<p class="wp-block-paragraph">The CA on its own is now ready to use, but for signing device certificates, we need a template. You can use <a href="https://smallstep.com/docs/step-ca/templates/#x509-templates">this example</a> for it. The file should be here: <br>/etc/step-ca/templates/certs/x509/leaf.tpl<br>It must also be added to the <a href="https://smallstep.com/docs/step-ca/templates/#adding-a-template-without-remote-provisioner-management">ca.json configuration</a>.</p>



<p class="wp-block-paragraph">We should also switch from file-based configuration to a database by  enabling the <a href="https://smallstep.com/docs/step-ca/provisioners/#remote-provisioner-management">remote provisioner management</a> feature.</p>



<h2 class="wp-block-heading"><strong>2. The Step Posture Connector</strong></h2>



<p class="wp-block-paragraph">The final step for the CA setup is the creation of a <a href="https://github.com/jedda/step-posture-connector/wiki/Setup-Guide#adding-webhooks-to-your-step-ca-acme-provisioner">webhook</a>. It is later used by the <a href="https://github.com/jedda/step-posture-connector">Step Posture Connector</a> to enable the CA to talk to Jamf and Apple.</p>



<pre class="wp-block-code"><code>step ca provisioner webhook add acme-da step-posture-connector --url https://localhost:9443/webhook/device-attest?mode=computer</code></pre>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="has-small-font-size wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> CA Configuration: /etc/step-ca/config/ca.json<br>No admin credentials found. You must login to execute admin commands.<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Please enter admin name/subject (e.g., name@example.com): step<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Provisioner: your.address@domain.name (JWK) <br>Please enter the password to decrypt the provisioner key:<br>Webhook ID: 5022a074-2b05-4n87-someMoreCharacters<br>Secret: ThisIsATopSecretWebhookSecretExample</p>
</blockquote>



<p class="wp-block-paragraph">As the Connector runs on the same server, we use localhost:9443 as URL. For Jamf Pro, we have to select the device type, as mobiles are handled differently as computers.</p>



<p class="wp-block-paragraph">Take a note of the Webhook-ID and the Secret, both are needed later.</p>



<p class="wp-block-paragraph">We should change the expiration period of the certificates, as in default they last only 24 hours. We chose 90 days =&gt; 2160 hours.</p>



<pre class="wp-block-code"><code>step ca provisioner update acme-da --x509-min-dur 20m --x509-default-dur 2160h</code></pre>



<p class="wp-block-paragraph">Our CA uses the <a href="https://github.com/jedda/step-posture-connector/releases">binary</a> for Step Posture Connector, not the Docker container. As it is a standard Linux server, we took the <a href="https://github.com/jedda/step-posture-connector/releases/download/v1.0.0/step-posture-connector_1.0.0_amd64">amd64</a> file. It is then copied to /srv/www/htdocs on the server.</p>



<p class="wp-block-paragraph">Also create a /srv/www/htdocs/ssl directory for the TLS certificates. Now we can use our CA to create the TLS certificates:</p>



<pre class="wp-block-code"><code>step ca certificate localhost server.pem server.key
# copy these to /srv/www/htdocs/ssl
cp server.pem /srv/www/htdocs/ssl/server.pem
cp server.key /srv/www/htdocs/ssl/server.key
# also copy the intermediate cert
cp /etc/step-ca/certs/intermediate_ca.crt /srv/www/htdocs/ssl/ca.pem</code></pre>



<p class="wp-block-paragraph">Since this certificate expires regularly, it has to be renewed, at best in a cronjob:</p>



<pre class="wp-block-code"><code>step ca renew --force /srv/www/htdocs/ssl/server.pem /srv/www/htdocs/ssl/server.key</code></pre>



<p class="wp-block-paragraph">We need a <a href="https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/API_Roles_and_Clients.html">Jamf API role</a> for the Connector, see also <a href="https://github.com/jedda/step-posture-connector?tab=readme-ov-file#provider-configuration---jamf-pro-jamf">here</a>. Take a note of the Jamf Client ID and Jamf Client Secret.</p>



<p class="wp-block-paragraph">All these go into the <strong>.env</strong> configuration file in /srv/www/htdocs/, see also <a href="https://github.com/jedda/step-posture-connector?tab=readme-ov-file#configuration">here</a>.</p>



<p class="wp-block-paragraph">Let&#8217;s start the connector and see, if everything is fine:</p>



<pre class="wp-block-code"><code>/srv/www/htdocs/step-posture-connector_1.0.0_amd64</code></pre>



<p class="wp-block-paragraph">Everything is fine? Then create a cronjob and start the Connector @reboot and in background. Consider running the Connector as a normal user, not as root.</p>



<h2 class="wp-block-heading"><strong>3. Jamf Configuration Profiles</strong></h2>



<p class="wp-block-paragraph">Now to the fun part. Create a Jamf configuration profile that contains your Root- and Intermediate Certificates (and also the certificate the network infrastructure uses), so the Macs trust your newly created CA.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.54.26.jpg"><img decoding="async" width="708" height="753" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.54.26.jpg" alt="" class="wp-image-492" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.54.26.jpg 708w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.54.26-282x300.jpg 282w" sizes="(max-width: 708px) 100vw, 708px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">The real fun starts now. Create a Jamf configuration profile with the ACME Payload, the certificate the network infrastructure uses and network configuration payload, all in one profile.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.57.40.jpg"><img decoding="async" width="645" height="771" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.57.40.jpg" alt="" class="wp-image-493" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.57.40.jpg 645w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-16.57.40-251x300.jpg 251w" sizes="(max-width: 645px) 100vw, 645px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">Let&#8217;s take a look at the details. The ACME payload sets the step-ca server, the encryption details, and enables attestation via MDA. The certificate&#8217;s Common Name (CN) is set to the serial number of the Mac, so we use the variable $SERIALNUMBER twice.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.07.45.jpg"><img loading="lazy" decoding="async" width="800" height="1004" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.07.45.jpg" alt="" class="wp-image-494" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.07.45.jpg 800w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.07.45-239x300.jpg 239w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.07.45-768x964.jpg 768w" sizes="auto, (max-width: 800px) 100vw, 800px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">The Network payload uses the just configured ACME certificate and also the additional certificate for trusting our Cisco ISE. We use EAP-TLS.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.12.jpg"><img loading="lazy" decoding="async" width="511" height="1020" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.12.jpg" alt="" class="wp-image-495" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.12.jpg 511w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.12-150x300.jpg 150w" sizes="auto, (max-width: 511px) 100vw, 511px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">The trust settings can be seen here:</p>



<figure class="wp-block-image size-large"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.31-1.jpg"><img loading="lazy" decoding="async" width="613" height="1024" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.31-1-613x1024.jpg" alt="" class="wp-image-497" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.31-1-613x1024.jpg 613w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.31-1-180x300.jpg 180w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.03.31-1.jpg 614w" sizes="auto, (max-width: 613px) 100vw, 613px" /></a><figcaption class="wp-element-caption">Screenshot</figcaption></figure>



<p class="wp-block-paragraph">When these configuration profiles are deployed, the Macs then get a certificate.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.35.55.jpg"><img loading="lazy" decoding="async" width="493" height="967" src="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.35.55.jpg" alt="" class="wp-image-498" srcset="https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.35.55.jpg 493w, https://tobir.org/wp-content/uploads/2025/07/Bildschirmfoto-2025-07-25-um-17.35.55-153x300.jpg 153w" sizes="auto, (max-width: 493px) 100vw, 493px" /></a><figcaption class="wp-element-caption"><br>Screenshot</figcaption></figure>



<p class="wp-block-paragraph">The sequence of the certificate generation with ACME protocol can be seen in this diagram. It shows, how all the components work together.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2025/07/ACME.png"><img loading="lazy" decoding="async" width="632" height="653" src="https://tobir.org/wp-content/uploads/2025/07/ACME.png" alt="" class="wp-image-499" srcset="https://tobir.org/wp-content/uploads/2025/07/ACME.png 632w, https://tobir.org/wp-content/uploads/2025/07/ACME-290x300.png 290w" sizes="auto, (max-width: 632px) 100vw, 632px" /></a></figure>



<p class="wp-block-paragraph">Sequence diagram of certificate generation with ACME.</p>



<p class="wp-block-paragraph">The certificates are valid for 90 days, they are automatically renewed, when the Macs are a part of the companies network, e.g. Wi-Fi or LAN on premise or via VPN.</p>



<h2 class="wp-block-heading"><strong>4. Network access</strong></h2>



<p class="wp-block-paragraph">Our Cisco ISE needed the Root- and Intermediate-certificates and imported them.</p>



<p class="wp-block-paragraph">When a Mac now connects to a network port, it shows the device certificate, the ISE matches the issuer of the certificate with the ones it imported before and if everything checks out, the ISE grants network access to a special, 802.1X protected subnet and the Mac gets an IP address.</p>



<p class="wp-block-paragraph">That&#8217;s it.</p>



<h2 class="wp-block-heading">5. Caveats</h2>



<p class="wp-block-paragraph"> It works fine with ARM Macs, with Intel Macs we&#8217;ve had some issues. The MDA has to be deactivated, thus only Intel Macs with <a href="https://github.com/HCSTech/scripts/blob/main/Extension%20Attributes/Controller%20Chip%20Type%20-%20T1%20or%20T2.xml">T2 chip</a> could possibly work, older would ones definitely not.</p>



<p class="wp-block-paragraph">Our T2 Macs failed to get a certificate, but they are going to be replaced anyway.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Update 01.08.2025: See <a href="https://tobir.org/part-2-of-the-acme-certificate-workflow/">part 2</a> for further configuration of the renewal process.</p>



<p class="wp-block-paragraph"></p>
<p>Der Beitrag <a href="https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/">How to get device certificates on Jamf-managed Macs via ACME with step-ca and use it to join a 802.1X secured network</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/how-to-get-device-certificates-on-jamf-managed-macs-via-acme-with-step-ca-and-use-it-to-join-a-802-1x-secured-network/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cisco Secure Client unter macOS 15 Sequoia Beta 1 installieren</title>
		<link>https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/</link>
					<comments>https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Fri, 14 Jun 2024 11:51:29 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Sequoia]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=483</guid>

					<description><![CDATA[<p>Mit dem neuen macOS 15 bin ich über ein Problem mit dem Cisco Secure Client gestolpert, man kann in der Version 5.1.2.42 und auch in 5.1.3.62 nicht mehr die notwendigen Berechtigungen setzen, damit der VPN Dienst richtig läuft. Als Konsequenz verweigert der Secure Client den Verbindungsaufbau zum VPN-Gateway. Als Fix, bis Cisco das selber mit &#8230; <a href="https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/" class="more-link"><span class="screen-reader-text">Cisco Secure Client unter macOS 15 Sequoia Beta 1 installieren</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/">Cisco Secure Client unter macOS 15 Sequoia Beta 1 installieren</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Mit dem neuen macOS 15 bin ich über ein Problem mit dem Cisco Secure Client gestolpert, man kann in der Version 5.1.2.42 und auch in 5.1.3.62 nicht mehr die notwendigen Berechtigungen setzen, damit der VPN Dienst richtig läuft. Als Konsequenz verweigert der Secure Client den Verbindungsaufbau zum VPN-Gateway.</p>



<p class="wp-block-paragraph">Als Fix, bis Cisco das selber mit einem neuen Release repariert, geht Folgendes:</p>



<p class="wp-block-paragraph">Öffne das Programm Terminal (aus Programme/Dienstprogramme) und gib dort folgende Befehle ein.</p>



<pre class="wp-block-code"><code>sudo cp /opt/cisco/secureclient/bin/Cisco\ Secure\ Client\ -\ AnyConnect\ VPN\ Service.app/Contents/Resources/com.cisco.secureclient.vpnagentd.plist /Library/LaunchDaemons/.

sudo launchctl bootstrap system /Library/LaunchDaemons/com.cisco.secureclient.vpnagentd.plist</code></pre>



<p class="wp-block-paragraph">Nach dem ersten wird man nach dem Admin-Passwort des Macs gefragt, dies dann dort eingeben und nicht wundern, dass es nicht angezeigt wird. </p>



<p class="wp-block-paragraph">Jetzt ändert sich der Cisco Eintrag bei den Anmeldeobjekten</p>



<figure class="wp-block-image size-large"><a href="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05.png"><img loading="lazy" decoding="async" width="1024" height="700" src="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05-1024x700.png" alt="" class="wp-image-485" srcset="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05-1024x700.png 1024w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05-300x205.png 300w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05-768x525.png 768w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05-1536x1050.png 1536w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.39.05.png 1586w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Nach einem Neustart des Macs läuft der Dienst anschließend, man kann eine VPN-Verbindung aufbauen.</p>



<figure class="wp-block-image size-large"><a href="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09.png"><img loading="lazy" decoding="async" width="1024" height="651" src="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09-1024x651.png" alt="" class="wp-image-484" srcset="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09-1024x651.png 1024w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09-300x191.png 300w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09-768x488.png 768w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09-1536x977.png 1536w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-13.41.09.png 1566w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">UPDATE: Man kann auch noch zusätzlich weiter unten bei den Anmeldeobjekten Erweiterungen aktivieren, insbesondere den Cisco Socket Filter.</p>



<figure class="wp-block-image size-large"><a href="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40.png"><img loading="lazy" decoding="async" width="1024" height="771" src="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40-1024x771.png" alt="" class="wp-image-488" srcset="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40-1024x771.png 1024w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40-300x226.png 300w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40-768x578.png 768w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40-1536x1157.png 1536w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.40.png 1620w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>



<figure class="wp-block-image size-large is-resized"><a href="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53.png"><img loading="lazy" decoding="async" width="1024" height="869" src="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53-1024x869.png" alt="" class="wp-image-489" style="width:516px;height:auto" srcset="https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53-1024x869.png 1024w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53-300x255.png 300w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53-768x652.png 768w, https://tobir.org/wp-content/uploads/2024/06/Bildschirmfoto-2024-06-14-um-17.02.53.png 1060w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
<p>Der Beitrag <a href="https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/">Cisco Secure Client unter macOS 15 Sequoia Beta 1 installieren</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/cisco-secure-client-unter-macos-15-sequoia-beta-1-installieren/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Statusmeldung bei mehreren Videochatprogrammen synchronisieren</title>
		<link>https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/</link>
					<comments>https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Tue, 27 Sep 2022 09:13:01 +0000</pubDate>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[kurzbefehle]]></category>
		<category><![CDATA[ms teams]]></category>
		<category><![CDATA[rocket.chat]]></category>
		<category><![CDATA[SetStatus]]></category>
		<category><![CDATA[shortcuts]]></category>
		<category><![CDATA[zoom]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=467</guid>

					<description><![CDATA[<p>Kennt Ihr das auch? Ihr seid gerade in einer Videokonferenz auf zoom und dann klingelt es in MS Teams und in Rocket.Chat trudeln noch Nachrichten ein. Oder ihr telefoniert gerade und Euch wollen die Leute parallel via Teams anrufen? Ich habe mir mit Applescript und den Kurzbefehlen einen Mechanismus gebaut, der auf Knopfdruck (also leider &#8230; <a href="https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/" class="more-link"><span class="screen-reader-text">Statusmeldung bei mehreren Videochatprogrammen synchronisieren</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/">Statusmeldung bei mehreren Videochatprogrammen synchronisieren</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Kennt Ihr das auch? Ihr seid gerade in einer Videokonferenz auf zoom und dann klingelt es in MS Teams und in Rocket.Chat trudeln noch Nachrichten ein. Oder ihr telefoniert gerade und Euch wollen die Leute parallel via Teams anrufen?</p>



<p class="wp-block-paragraph">Ich habe mir mit Applescript und den Kurzbefehlen einen Mechanismus gebaut, der auf Knopfdruck (also leider nicht vollautomatisch) die anderen Videochatprogramme auf <em>DoNotDisturb</em> <em>(DND) </em>beziehungsweise auf <em>Nicht stören</em> setzt, wenn man in dem anderen Programm gerade beschäftigt ist. Außerdem werden Systembenachrichtigungen stumm geschaltet über die Fokus-App. </p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2022/09/menu.jpg"><img loading="lazy" decoding="async" width="401" height="277" src="https://tobir.org/wp-content/uploads/2022/09/menu.jpg" alt="" class="wp-image-469" srcset="https://tobir.org/wp-content/uploads/2022/09/menu.jpg 401w, https://tobir.org/wp-content/uploads/2022/09/menu-300x207.jpg 300w" sizes="auto, (max-width: 401px) 100vw, 401px" /></a><figcaption>Hier ist das Kurzbefehle-Menü zu sehen mit den entsprechenden Einträgen für Teams, Zoom und Telefon.</figcaption></figure>



<p class="wp-block-paragraph">Wählt man beispielsweise <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26d4.png" alt="⛔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>zoom DND</strong> aus, so wird in MS Teams und Rocket.Chat der Status auf <em>DoNotdisturb</em> gesetzt. Bei der Auswahl von <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>zoom Avail</strong> dann entsprechend wieder auf <em>Available</em> beziehungsweise <em>Verfügbar</em>. Genauso funktioniert es bei der Auswahl von <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26d4.png" alt="⛔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Teams DND</strong>, nur dass der Status in zoom nicht über das Menü einstellbar ist, daher wird zoom dann geschlossen und bei <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Teams Avail</strong> dann wieder automatisch gestartet.</p>



<p class="wp-block-paragraph">Der Eintrag <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26d4.png" alt="⛔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Telefon DND</strong> bringt alle drei Programme in den entsprechenden Modus, nicht nur ausgewählte.</p>



<p class="wp-block-paragraph">Wie funktioniert das ganze? Ich habe folgende Applescript-Dateien angelegt und führe diese Skripte aus, wenn über die Kurzbefehle-App einer der obigen Einträge ausgewählt wurde. </p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2022/09/shortcuts.jpg"><img loading="lazy" decoding="async" width="804" height="401" src="https://tobir.org/wp-content/uploads/2022/09/shortcuts.jpg" alt="" class="wp-image-470" srcset="https://tobir.org/wp-content/uploads/2022/09/shortcuts.jpg 804w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-300x150.jpg 300w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-768x383.jpg 768w" sizes="auto, (max-width: 804px) 100vw, 804px" /></a><figcaption>Die im Menü anzuzeigenden Einträge lassen sich in der Kurzbefehle-App verwalten.</figcaption></figure>



<p class="wp-block-paragraph">Gucken wir uns einmal den <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26d4.png" alt="⛔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Teams DND</strong> Eintrag genauer an. Zuerst wird ein Shell-Skript ausgeführt, welches zoom auf DND setzt. Ok, ist etwas geschummelt, habe ich oben ja schon geschrieben, das Skript beendet zoom. Anschließend wird per API Aufruf der Status in Rocket.Chat angepasst und am Ende Fokus <em>Videokonferenz</em> aktiviert.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2022/09/shortcuts-details.jpg"><img loading="lazy" decoding="async" width="914" height="617" src="https://tobir.org/wp-content/uploads/2022/09/shortcuts-details.jpg" alt="" class="wp-image-471" srcset="https://tobir.org/wp-content/uploads/2022/09/shortcuts-details.jpg 914w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-details-300x203.jpg 300w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-details-768x518.jpg 768w" sizes="auto, (max-width: 914px) 100vw, 914px" /></a><figcaption>Der Ablauf des Teams DND Skriptes.</figcaption></figure>



<p class="wp-block-paragraph">Das wieder auf <em>Verfügbar</em> schalten können wir uns am Beispiel von <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>zoom Avail</strong> anschauen. Zuerst wird MS Teams auf <em>Available</em> geschaltet, dann Rocket.Chat und am Ende wird der Fokus wieder deaktiviert.</p>



<figure class="wp-block-image size-full"><a href="https://tobir.org/wp-content/uploads/2022/09/shortcuts-avail.jpg"><img loading="lazy" decoding="async" width="791" height="634" src="https://tobir.org/wp-content/uploads/2022/09/shortcuts-avail.jpg" alt="" class="wp-image-472" srcset="https://tobir.org/wp-content/uploads/2022/09/shortcuts-avail.jpg 791w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-avail-300x240.jpg 300w, https://tobir.org/wp-content/uploads/2022/09/shortcuts-avail-768x616.jpg 768w" sizes="auto, (max-width: 791px) 100vw, 791px" /></a><figcaption>Der Ablauf des zoom Available Skriptes.</figcaption></figure>



<p class="wp-block-paragraph">Beim Telefon-Eintrag werden Zoom, Teams und Rocket.Chat entsprechend geschaltet, also alle auf <em>DND</em> oder <em>Verfügbar</em>.</p>



<p class="wp-block-paragraph">Wenn man die Skripte in die iCloud legt, kann man sie auf verschiedenen Macs verwenden. Das macht der Skripteditor standardmäßig. Die Kurzbefehle lassen sich ebenso teilen.</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><a href="https://tobir.org/wp-content/uploads/2022/09/scripts.jpg"><img loading="lazy" decoding="async" width="217" height="181" src="https://tobir.org/wp-content/uploads/2022/09/scripts.jpg" alt="" class="wp-image-474"/></a><figcaption>Die einzelnen Skripte zum Ändern des Status.</figcaption></figure>
</div>


<p class="wp-block-paragraph">Den Quellcode für die einzelnen Applescript-Dateien habe ich auf github hochgeladen: <a href="https://github.com/tobir/videochat-applescripts" target="_blank" rel="noreferrer noopener">https://github.com/tobir/videochat-applescripts</a></p>



<p class="wp-block-paragraph">Viel Spaß beim Nachbauen!</p>
<p>Der Beitrag <a href="https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/">Statusmeldung bei mehreren Videochatprogrammen synchronisieren</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/statusmeldung-bei-mehreren-videochatprogrammen-synchronisieren/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Komplikationen auf Apple Watch verschwunden</title>
		<link>https://tobir.org/komplikationen-auf-apple-watch-verschwunden/</link>
					<comments>https://tobir.org/komplikationen-auf-apple-watch-verschwunden/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Tue, 30 Jun 2020 08:36:13 +0000</pubDate>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Smartwatch]]></category>
		<category><![CDATA[Apple Watch]]></category>
		<category><![CDATA[Komplikationen]]></category>
		<category><![CDATA[Wetter App]]></category>
		<guid isPermaLink="false">https://tobir.org/?p=449</guid>

					<description><![CDATA[<p>Auf der Apple Watch sind Standard Komplikationen verschwunden. Die zugehörige App wurde auf dem iPhone deinstalliert. Keine gute Idee.</p>
<p>Der Beitrag <a href="https://tobir.org/komplikationen-auf-apple-watch-verschwunden/">Komplikationen auf Apple Watch verschwunden</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Mir ist beim Auswählen eines neuen Watch Themes aufgefallen, dass auf einmal die Komplikationen für Wetter, Regen und Temperatur verschwunden waren. Da dies Standard-Komplikationen von Apple waren kam mir das komisch vor. Nach einigem Suchen im Internet fand ich zwei Vorschläge: Neu Starten oder erneutes Koppeln der Uhr mit dem Smartphone. Leider hat beides das Problem aber nicht behoben.</p>



<p class="wp-block-paragraph">Nun fiel mir ein, dass ich neulich meinen Homescreen aufgeräumt hatte, dabei ist auch die Wetter App von Apple deinstalliert worden. Ich verwende lieber die von Weather Pro. Die Wetter Komplikationen sind aber ein Teil der Apple Wetter App, daher sind diese dann automatisch mit deinstalliert worden.</p>



<p class="wp-block-paragraph">Als ich auf dem iPhone die Wetter App wieder installiert hatte waren die Komplikationen auch wieder auf der Uhr verfügbar.</p>
<p>Der Beitrag <a href="https://tobir.org/komplikationen-auf-apple-watch-verschwunden/">Komplikationen auf Apple Watch verschwunden</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/komplikationen-auf-apple-watch-verschwunden/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Jailbreak iOS 8.4 möglich</title>
		<link>https://tobir.org/jailbreak-ios-8-4-moeglich/</link>
					<comments>https://tobir.org/jailbreak-ios-8-4-moeglich/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Wed, 01 Jul 2015 12:34:16 +0000</pubDate>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[ios8]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<guid isPermaLink="false">http://tobir.org/?p=338</guid>

					<description><![CDATA[<p>Seit gestern hat Apple iOS 8.4 freigegeben, kurz danach wurde ein Update für den Jailbreak von TaiG veröffentlicht, der nun auch iOS 8.4 unterstützt. Zur Zeit ist es also noch möglich, iOS 8.3 und 8.4 zu jailbreaken, wobei die Unterstützung für iOS 8.3 demnächst eingestellt werden sollte, da Apple diese Vorgängerversion bald nicht mehr signieren &#8230; <a href="https://tobir.org/jailbreak-ios-8-4-moeglich/" class="more-link"><span class="screen-reader-text">Jailbreak iOS 8.4 möglich</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/jailbreak-ios-8-4-moeglich/">Jailbreak iOS 8.4 möglich</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Seit gestern hat Apple iOS 8.4 freigegeben, kurz danach wurde ein Update für den Jailbreak von TaiG veröffentlicht, der nun auch iOS 8.4 unterstützt.<br />
Zur Zeit ist es also noch möglich, iOS 8.3 und 8.4 zu jailbreaken, wobei die Unterstützung für iOS 8.3 demnächst eingestellt werden sollte, da Apple diese Vorgängerversion bald nicht mehr signieren wird. Damit ist dann das installieren der alten Firmware nicht mehr möglich.<br />
Außerdem existiert das Programm zum jailbreaken momentan nur für Windows.</p>
<p>Eine gute englischsprachige Anleitung gibt es bei <a href="http://www.redmondpie.com/jailbreak-ios-8.4-using-taig-v2.2-on-iphone-ipad-how-to-tutorial/">www.redmondpie.com</a>, es sind aber ein paar Stolpersteine aus dem Weg zu räumen.</p>
<ul>
<li>Codesperre ausschalten</li>
<li>Finde mein iPhone ausschalten</li>
<li>Flugzeugmodus anschalten</li>
</ul>
<p>Die ersten beiden Punkte werden auch in der Anleitung erwähnt, den dritten habe ich im dortigen Supportforum als Tipp entdeckt.</p>
<p>Da nun die Unterstützung für iOS 8.4 ziemlich frisch ist, sind viele Tools noch nicht für iOS 8.4 getestet bzw. werden als nicht kompatibel angezeigt. Dies wird sich wie bisher auch im Laufe der Zeit ändern, wenn die Entwickler die Programme entsprechend anpassen.</p>
<p>Bis nun im Herbst iOS9 erscheinen wird, ist der Jailbreak für iOS 8.4 wahrscheinlich der Stand, auf dem man das iPhone längere Zeit betreiben möchte.</p>
<p>Der Beitrag <a href="https://tobir.org/jailbreak-ios-8-4-moeglich/">Jailbreak iOS 8.4 möglich</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/jailbreak-ios-8-4-moeglich/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Probleme beim Update auf OSX 10.10 Yosemity</title>
		<link>https://tobir.org/probleme-mit-osx-10-10-yosemity/</link>
					<comments>https://tobir.org/probleme-mit-osx-10-10-yosemity/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Sun, 19 Oct 2014 09:11:49 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[10.10]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[Yosemity]]></category>
		<guid isPermaLink="false">http://tobir.org/?p=313</guid>

					<description><![CDATA[<p>Falls Ihr ein Update auf OSX 10.10 Yosemity vorgenommen habt, könntet Ihr über ein paar Probleme gestolpert sein, die bei einer Neuinstallation auf einer sauberen Platte nicht vorkommen. Latex und Homebrew Vor dem Update sollte man selbst installierte Programme aus /usr/local/ verschieben, da sonst das Update mehrere Stunden dauern kann. Dazu das Terminal-Programm starten und &#8230; <a href="https://tobir.org/probleme-mit-osx-10-10-yosemity/" class="more-link"><span class="screen-reader-text">Probleme beim Update auf OSX 10.10 Yosemity</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/probleme-mit-osx-10-10-yosemity/">Probleme beim Update auf OSX 10.10 Yosemity</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Falls Ihr ein Update auf OSX 10.10 Yosemity vorgenommen habt, könntet Ihr über ein paar Probleme gestolpert sein, die bei einer Neuinstallation auf einer sauberen Platte nicht vorkommen.</p>
<h3>Latex und Homebrew</h3>
<p><strong>Vor dem Update</strong> sollte man selbst installierte Programme aus <code>/usr/local/</code> verschieben, da sonst das Update mehrere Stunden dauern kann.</p>
<p>Dazu das <code>Terminal</code>-Programm starten und z.B. die LaTex-Installation ins Nutzerverzeichnis umziehen:<br />
<strong><em>sudo mv /usr/local/texlive ~</em></strong><br />
Hier muss noch das Admin-Passwort eingegeben werden.<br />
Nun kann das Update auf OSX 10.10 erfolgen.<br />
Danach muss das Ganze wieder zurück, dazu folgendes eingeben:<br />
<strong><em>sudo mv ~/texlive /usr/local</em></strong></p>
<p>Dies gilt ebenso für Homebrew oder andere Programme, die unter <code>/usr/local/</code> Dateien ablegen.<br />
Nicht mehr benötigte, alte LaTex-Installationen sollte man vorher finden und löschen über:<br />
<strong><em>ls -l /usr/local/texlive/</em></strong><br />
<strong><em>sudo rm -r /usr/local/texlive/2012/</em></strong> für LaTex 2012 z.B.</p>
<h3>Reste vom alten Betriebssystem</h3>
<p><strong>Nach dem Update</strong> hatte ich noch Reste des Vorgänger-Betriebssystems gespeichert unter: <code>/Previous System/</code>. Beim Versuch, dieses Verzeichnis zu löschen bekam ich die Fehlermeldung, das der Zugriff verweigert werde. Das Problem ist anscheinend eine Datei mit Namen <code>sleepimage</code>, welche besondere Berechtigungen aufweist. Diese muss man der Datei erst entziehen, damit man den Ordner löschen kann.</p>
<p>Dazu gibt man folgendes im <code>Terminal</code>-Programm ein und gibt das Admin-Passwort ein:<br />
<strong><em>sudo chflags noschg /Previous System/private/var/vm/sleepimage</em></strong><br />
Anschließend kann man die Datei löschen mit:<br />
<strong><em>sudo rm /Previous System/private/var/vm/sleepimage</em></strong><br />
Nun kann man den Ordner /Previous System/ in den Papierkorb ziehen und diesen löschen.</p>
<p>Der Beitrag <a href="https://tobir.org/probleme-mit-osx-10-10-yosemity/">Probleme beim Update auf OSX 10.10 Yosemity</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/probleme-mit-osx-10-10-yosemity/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Jailbreak unter iOS7 und Cydia Empfehlungen</title>
		<link>https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/</link>
					<comments>https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/#respond</comments>
		
		<dc:creator><![CDATA[tobi]]></dc:creator>
		<pubDate>Fri, 10 Jan 2014 13:08:59 +0000</pubDate>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Cydia]]></category>
		<category><![CDATA[iOS7]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<guid isPermaLink="false">http://tobir.org/?p=252</guid>

					<description><![CDATA[<p>Es existiert endlich ein Untethered-Jailbreak für iPhones, iPods und iPads mit iOS 7.0 bis 7.0.4. Für iOS 6 hatte ich schon folgendes veröffentlicht: http://tobir.org/iphone-ios-6-jailbreak-und-empfehlungen-fur-cydia/ Diesen Jailbreak mit Namen evasi0n, sowie den für iOS6  hat das Team evad3rs entwickelt. Infos zum Verfahren des Jailbreaks und Hilfe findet man z.B. hier: http://iclarified.com Auf dem Gerät befindet sich &#8230; <a href="https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/" class="more-link"><span class="screen-reader-text">Jailbreak unter iOS7 und Cydia Empfehlungen</span> weiterlesen</a></p>
<p>Der Beitrag <a href="https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/">Jailbreak unter iOS7 und Cydia Empfehlungen</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Es existiert endlich ein Untethered-Jailbreak für iPhones, iPods und iPads mit iOS 7.0 bis 7.0.4. Für iOS 6 hatte ich schon folgendes veröffentlicht:<br />
<a href="http://tobir.org/iphone-ios-6-jailbreak-und-empfehlungen-fur-cydia/">http://tobir.org/iphone-ios-6-jailbreak-und-empfehlungen-fur-cydia/</a></p>
<p>Diesen Jailbreak mit Namen <em>evasi0n</em>, sowie den für iOS6  hat das Team <em>evad3rs</em> entwickelt.<br />
Infos zum Verfahren des Jailbreaks und Hilfe findet man z.B. hier:<br />
<a href="http://iclarified.com">http://iclarified.com</a></p>
<p>Auf dem Gerät befindet sich nach dem Jailbreak nun der alternative AppStore Cydia.<br />
Dort gibt es mittlerweile einige Erweiterungen und Programme, die das Gerät noch besser nutzbar machen bzw. die es um Funktionen erweitern, die Apple nicht vorgesehen hatte.</p>
<h3>Meine Favoriten bei Cydia, die auch unter IOS 7 laufen, werde ich im Folgenden etwas erläutern.</h3>
<ul>
<li><em>AlwaysClear</em>: Blendet das Löschen-Symbol im NotificationCenter ein</li>
<li><em>Calendar for Lockscreen: </em><strong>Kostenpflichtig</strong>, blendet Kalendereinträge im LS ein</li>
<li><em>CCSettings</em>: Blendet mehr Schalter wie z.B. VPN, 3G im Control Center ein</li>
<li><em>CyDelete7</em>: Ermöglicht das Löschen von Cydia-Apps wie gewöhnliche Apps</li>
<li><em>Edit Alarms:</em> Die Weckerzeiten direkt bearbeiten</li>
<li><em>f.lux</em>: Passt die Helligkeit und Farbtemperatur an die Beleuchtungssituation an</li>
<li><em>FakeCarrier</em>: Eigenen Providernamen anzeigen</li>
<li><em>FiveIconDock</em>: Ermöglicht fünf anstatt vier Icons unten im Dock</li>
<li><em>iCaughtU: </em>Diebstahlsicherung, die Fotos beim fehlerhaften Entsperren erstellt</li>
<li><em>Infinifolders: </em><strong>Kostenpflichtig</strong>, dafür hat man in Ordnern mehr Möglichkeiten</li>
<li><em>MultiIconMover:</em>Mehrere Icons auf einmal verschieben</li>
<li><em>OpenSSH: </em>SSH-Server, für SSH-Zugriff aufs iPhone (<strong>root-Passwort ändern</strong>!)</li>
<li><em>PowerSoundDisabler:</em>Keine Töne oder Vibrationen beim Anschluss an Strom</li>
<li><em>PrivaCy: </em>Datensammeln und ausspionieren unterbinden</li>
<li><em>Protect My Privacy</em>: Zugriff von Apps aufs Adressbuch etc. steuern</li>
<li><em>Purge: </em>Alle Apps auf einmal aus dem Taskmanager entfernen</li>
<li><em>SwipeShiftCaret</em>: Zur einfacheren Korrektur von Text-Eingaben</li>
</ul>
<p>Leider sind viele der &#8222;alten&#8220; Tools noch nicht IOS7-kompatibel aber daran ändert sich hoffentlich bald etwas, da die Entwicklung ja in vollem Gange ist.</p>
<p>Übrigens kann man den Jailbreak rückgängig machen, wenn man über iTunes Wiederherstellen des iPhones auswählt.</p>
<p><strong>Update</strong>: Habe die Liste noch um ein paar Punkte ergänzt.</p>
<p>Der Beitrag <a href="https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/">Jailbreak unter iOS7 und Cydia Empfehlungen</a> erschien zuerst auf <a href="https://tobir.org">Tobi&#039;s Tipps</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://tobir.org/jailbreak-unter-ios7-und-cydia-empfehlungen/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
