TweetFollow Us on Twitter

An Apple Remote Desktop Critique

Volume Number: 20 (2004)
Issue Number: 12
Column Tag: Programming

Patch Panel

An Apple Remote Desktop Critique

ARD is Much Better in Version 2.1, But Still Needs A Lot of Work

by John Welch

As you can tell from the title, this article is going to be a critique of Apple's remote system management tool, Apple Remote Desktop, or ARD, to the, well, ARD cognoscenti. While it is, especially in version 2.1, a much improved tool over earlier versions, (it's actually useful to more than just K-12 lab Admins now), it still has a few critical areas that need work if it is to move into the next level.

Packaging

ARD needs to be bundled with Mac OS X Server, period. To sell a server that can handle thousands of clients, and then give no way to manage those clients without laying out another few hundred dollars is silly. If I'm buying an Xserve, I need client management tools. It's not like Apple has to license it, and there's no problem with selling it separately, but it needs to be shipped as part of Mac OS X Server. I still see people on mailing lists trying to do things manually, when ARD would be a great help, but after having spent money on Server, there's sometimes a bit of a hurdle getting another P.O. approved because Apple doesn't' think you need client management tools as a part of their server. Compare this to Active Directory, which ships with basic client management as part of Windows Server. Bundling ARD with Mac OS X Server would fill a basic need of network administrators everywhere. (Yes, Apple does ship SSH with Mac OS X, and they do have excellent command line tools. However, the documentation for those tools is a bit...shall we say light.)

Even better: integrate ARD in with Server Admin and Workgroup Manager. This would allow an administrator, when setting up a remote client or user in Workgroup Manager, to easily bring up the client in an ARD window, and test out the various login settings, MCX settings, etc. Integration with Server Admin would allow administrators to better deal with various tools that work better when you can see the screen, or allow administrators who are not yet comfortable with the command line to not have to start swimming in the deep end of the pool, with the drain suction on 'high'.

Another issue for the enterprise is the pricing. At first glance, ARD is one of the cheapest tools out there. However, that's more for if you have a single, or very limited number of administration workstations. In a large network, or an enterprise setup, that's not always going to be the case. If you need multiple administration machines, ARD's price starts to go up in $500US increments. What is needed is perhaps an "Enterprise" version that would allow for unlimited administration workstations in a root domain, so for example, you could have unlimited administration workstations for company.com, and that would include all the subdomains a company might have, like nyc.company.com, etc. This could be based either on DNS, or (more logically), Open Directory domains.

Automation

Another area where ARD suffers is in automation. True, you can now run shell commands directly on clients, but that's a rather manual process. There's no provision for kicking off other commands based on the results, because the ARD itself cannot be scripted, via shell, or AppleScript. Which means that while I can run softwareupdate -l on 500 Macs, I can't have the results of that kick of any automated update process. Automation is critical to administrators, because as your client base goes up, your workload tends to increase by multiples of that increase. A tool that almost lets you automate, or forces you to have manual steps with what little automation it allows you to do is almost a hindrance, not a help.

ARD needs full OSA and shell support, so that automation can happen independently of language provisions. Mac OS X is living in a world of shell, AppleScript, python, Perl, and . While it would be ridiculous to expect Apple to create interfaces for a dozen different languages, full OSA support, (including the ability to directly use shell as an OSA language, something long overdue in OS X), would create the interface so that administrators could use whatever language they feel most productive with, or need to use for their specific workflow.

By implementing OSA support in AppleScript, ARD would become a much better, and more capable tool. If you look at almost any other administration tool on any other platform, they're all scriptable. In fact, there are sites devoted to custom implementations of things like Active Directory tools, Nagios, MRTG, etc., and almost all of them are collections of scripts that someone else decided to donate to a larger community so that their work could benefit others. This kind of community is critical to administrators using those tools, but there's no way to do this kind of thing in ARD.

Directory Service Integration

Mac OS X Server is based on Open Directory, so is Mac OS X. Open Directory is at the heart of everything Apple does for managing machines, yet ARD is resolutely ignorant of Open Directory. Again, yet another way that ARD makes life harder than it should be on its users. There needs to be, as part of integration with Server Admin, a setting that allows you to assign usage privileges to ARD based on user and group settings. So you could create an ARD administrator group or groups, each having different levels of access. This way, creating a new ARD user is a matter of drag and drop in Workgroup Manager. This doesn't require the upcoming ACL structure in Mac OS X 10.4, aka Tiger. Those of course, would make it simpler, because ARD privileges could be a separate ACL setting, which could be applied across a directory.

This is not to say that ARD should require an Open Directory setup to function. That would be just as big of a mistake in the opposite direction. But the need for a client management tool to plug into the client management infrastructure is too obvious to ignore.

Interface and Functional Issues

The rest of any problems with ARD are interface/functional issues. For example, while copying files from the administration workstation to clients is quite simple, copying files from the client to the administration workstation forces you to do a find, find the files you need in the result of the find, click copy, then pick the destination. While this is great if you need to copy one or two files from a couple hundred workstations, that's not how that particular operation works in a large percentage of cases. (Where you see that particular model used the most is in a lab setup. However, Apple networks aren't just for K-12, or Higher Ed labs anymore, and tools like ARD need to reflect this.) For a single file, or folder, ARD should just let you drag it from the client workstation to the administration workstation the same way that you would move files and folders from a network share to your local hard drive. This is also where a scripting interface would be more than a little handy. Being able to use the Unix locate or find tools with ARD would not make administrators cry.

While it's great that Apple is using VNC as the low-level protocol, they haven't done a lot to help ARD users who are not familiar with VNC to more easily get ARD talking to Windows or Linux boxes running VNC. Again, the mailing lists are full of the same kind of question, which shows the difference between merely making a feature available, and making it useful. Spending a little more time to make using the VNC feature easier would pay off quite well.

ARD also needs to talk to other installers. Yes, in a perfect world, (or at least Apple's definition of one) we all use drag and drop disk images, or Apple's Installer. However, in the real world that we all have to work in, we don't. For example, since Installer VISE is cross platform, and Apple's Installer is not, it makes little sense for a company like Adobe, where you have a great deal of similarity between the Mac and Windows versions of their software, to not use an installer technology that saves them time and money by allowing them to use one tool for all their installer needs. Apple needs to recognize this, and either integrate both Allume's Stuffit InstallerMaker, and MindVision's Installer VISE into ARD, or build a plugin architecture into ARD with a proper API so that third parties can extend ARD as needed. (The plugin architecture, while not the best short - term solution, ends up being the better long-term solution for this problem, and every other problem that we haven't even encountered yet. Just ask Adobe and Quark about how beneficial plugins are.) The "just install and image" or "just install, then repackage" arguments are workarounds for NIH, not solutions for the enterprise, (whatever your definition of 'enterprise' is. I worked at MIT, I'll put their network up against any similarly sized corporate network any day of the week. '.edu' does not mean 'tinkertoy'.)

Another issue is security. ARD needs to be able to connect through SSH tunnels as a basic functional part of the client and the administration workstations. SSH ships with Mac OS X, and should be integrated into the connection setup by default. Any kind of administrative connection across a network of any kind needs to be secure by default, and by known, trusted measures. Since Mac OS X and Mac OS X server ship with multiple secure authentication and encryption methods, (SSH, SSL, Kerberos), and Apple uses SSL in its other administration tools, such as Server Admin, there's little reason for not having ARD plug into these methods as well. It's one thing to say "It's secure, trust us" and another thing to say, "It's secure, here are the industry standard methods we use". (Note: Yes, I'm aware that you can manually tunnel ARD or anything else through SSH. That's not the point. It shouldn't require manual or even shell scripted setup. It should be an enabled-by-default checkbox on the install, enabled by default in the client and administration configuration, and enabled by default in the usage. Secure modes of operation need to be the unconscious default, not the manual option.)

Conclussion

Again, ARD has steadily improved throughout its history, and the features in version 2, now 2.1 are enough of an improvement for me to switch over to it from Timbuktu. The integration with VNC was brilliant and obvious, and I'm glad to see that Apple agreed with everyone else on this.

Most of what I base this critique on are things that constitute the "last 20% of excellence". (From the idea that the first 80% of work on a product make it functional and 'good enough', but it's the last 20% that make it "insanely great". Microsoft is the master of the first 80%, but Apple is the master of the last 20%, and that difference shows in almost everything they do.) ARD is so close to being one of the top - notch client management tools on any platform (and on every platform with VNC), and with just a little massaging, it'll get there.


John Welch (jwelch@provar.com) is an IT Staff Member for Kansas City Life Insurance, a Technical Strategist for Provar, (http://www.provar.com/) and the Chief Know-It-All for TackyShirt, (http://www.tackyshirt.com/. He has over fifteen years of experience at making Macs work with other computer systems. John specializes in figuring out ways in which to make the Mac do what nobody thinks it can, showing that the Mac is a superior administrative platform, and teaching others how to use it in interesting, if sometimes frightening ways. He also does things that don't involve computertry on occasion, or at least that's the rumor.

 
AAPL
$501.11
Apple Inc.
+2.43
MSFT
$34.64
Microsoft Corpora
+0.15
GOOG
$898.03
Google Inc.
+16.02

MacTech Search:
Community Search:

Software Updates via MacUpdate

CrossOver 12.5.1 - Run Windows apps on y...
CrossOver can get your Windows productivity applications and PC games up and running on your Mac quickly and easily. CrossOver runs the Windows software that you need on Mac at home, in the office,... Read more
Paperless 2.3.1 - Digital documents mana...
Paperless is a digital documents manager. Remember when everyone talked about how we would soon be a paperless society? Now it seems like we use paper more than ever. Let's face it - we need and we... Read more
Apple HP Printer Drivers 2.16.1 - For OS...
Apple HP Printer Drivers includes the latest HP printing and scanning software for Mac OS X 10.6, 10.7 and 10.8. For information about supported printer models, see this page.Version 2.16.1: This... Read more
Yep 3.5.1 - Organize and manage all your...
Yep is a document organization and management tool. Like iTunes for music or iPhoto for photos, Yep lets you search and view your documents in a comfortable interface, while offering the ability to... Read more
Apple Canon Laser Printer Drivers 2.11 -...
Apple Canon Laser Printer Drivers is the latest Canon Laser printing and scanning software for Mac OS X 10.6, 10.7 and 10.8. For information about supported printer models, see this page.Version 2.11... Read more
Apple Java for Mac OS X 10.6 Update 17 -...
Apple Java for Mac OS X 10.6 delivers improved security, reliability, and compatibility by updating Java SE 6.Version Update 17: Java for Mac OS X 10.6 Update 17 delivers improved security,... Read more
Arq 3.3 - Online backup (requires Amazon...
Arq is online backup for the Mac using Amazon S3 and Amazon Glacier. It backs-up and faithfully restores all the special metadata of Mac files that other products don't, including resource forks,... Read more
Apple Java 2013-005 - For OS X 10.7 and...
Apple Java for OS X 2013-005 delivers improved security, reliability, and compatibility by updating Java SE 6 to 1.6.0_65. On systems that have not already installed Java for OS X 2012-006, this... Read more
DEVONthink Pro 2.7 - Knowledge base, inf...
Save 10% with our exclusive coupon code: MACUPDATE10 DEVONthink Pro is your essential assistant for today's world, where almost everything is digital. From shopping receipts to important research... Read more
VirtualBox 4.3.0 - x86 virtualization so...
VirtualBox is a family of powerful x86 virtualization products for enterprise as well as home use. Not only is VirtualBox an extremely feature rich, high performance product for enterprise customers... Read more

Briquid Gets Updated with New Undo Butto...
Briquid Gets Updated with New Undo Button, Achievements, and Leaderboards, on Sale for $0.99 Posted by Andrew Stevens on October 16th, 2013 [ | Read more »
Halloween – iLovecraft Brings Frightenin...
Halloween – iLovecraft Brings Frightening Stories From Author H.P. | Read more »
The Blockheads Creator David Frampton Gi...
The Blockheads Creator David Frampton Gives a Postmortem on the Creation Process of the Game Posted by Andrew Stevens on October 16th, 2013 [ permalink ] Hey, a | Read more »
Sorcery! Enhances the Gameplay in Latest...
Sorcery! | Read more »
It Came From Australia: Tiny Death Star
NimbleBit and Disney have teamed up to make Star Wars: Tiny Death Star, a Star Wars take on Tiny Tower. Right now, the game is in testing in Australia (you will never find a more wretched hive of scum and villainy) but we were able to sneak past... | Read more »
FIST OF AWESOME Review
FIST OF AWESOME Review By Rob Rich on October 16th, 2013 Our Rating: :: TALK TO THE FISTUniversal App - Designed for iPhone and iPad A totalitarian society of bears is only the tip of the iceberg in this throwback brawler.   | Read more »
PROVERBidioms Paints English Sayings in...
PROVERBidioms Paints English Sayings in a Picture for Users to Find Posted by Andrew Stevens on October 16th, 2013 [ permalink ] | Read more »
OmniFocus 2 for iPhone Review
OmniFocus 2 for iPhone Review By Carter Dotson on October 16th, 2013 Our Rating: :: OMNIPOTENTiPhone App - Designed for the iPhone, compatible with the iPad OmniFocus 2 for iPhone is a task management app for people who absolutely... | Read more »
Ingress – Google’s Augmented-Reality Gam...
Ingress – Google’s Augmented-Reality Game to Make its Way to iOS Next Year Posted by Andrew Stevens on October 16th, 2013 [ permalink ] | Read more »
CSR Classics is Full of Ridiculously Pre...
CSR Classics is Full of Ridiculously Pretty Classic Automobiles Posted by Rob Rich on October 16th, 2013 [ permalink ] | Read more »

Price Scanner via MacPrices.net

Apple Store Canada offers refurbished 11-inch...
 The Apple Store Canada has Apple Certified Refurbished 2013 11″ MacBook Airs available starting at CDN$ 849. Save up to $180 off the cost of new models. An Apple one-year warranty is included with... Read more
Updated MacBook Price Trackers
We’ve updated our MacBook Price Trackers with the latest information on prices, bundles, and availability on MacBook Airs, MacBook Pros, and the MacBook Pros with Retina Displays from Apple’s... Read more
13-inch Retina MacBook Pros on sale for up to...
B&H Photo has the 13″ 2.5GHz Retina MacBook Pro on sale for $1399 including free shipping. Their price is $100 off MSRP. They have the 13″ 2.6GHz Retina MacBook Pro on sale for $1580 which is $... Read more
AppleCare Protection Plans on sale for up to...
B&H Photo has 3-Year AppleCare Warranties on sale for up to $105 off MSRP including free shipping plus NY sales tax only: - Mac Laptops 15″ and Above: $244 $105 off MSRP - Mac Laptops 13″ and... Read more
Apple’s 64-bit A7 Processor: One Step Closer...
PC Pro’s Darien Graham-Smith reported that Canonical founder and Ubuntu Linux creator Mark Shuttleworth believes Apple intends to follow Ubuntu’s lead and merge its desktop and mobile operating... Read more
MacBook Pro First, Followed By iPad At The En...
French site Info MacG’s Florian Innocente says he has received availability dates and order of arrival for the next MacBook Pro and the iPad from the same contact who had warned hom of the arrival of... Read more
Chart: iPad Value Decline From NextWorth
With every announcement of a new Apple device, serial upgraders begin selling off their previous models – driving down the resale value. So, with the Oct. 22 Apple announcement date approaching,... Read more
SOASTA Survey: What App Do You Check First in...
SOASTA Inc., the leader in cloud and mobile testing announced the results of its recent survey showing which mobile apps are popular with smartphone owners in major American markets. SOASTA’s survey... Read more
Apple, Samsung Reportedly Both Developing 12-...
Digitimes’ Aaron Lee and Joseph Tsai report that Apple and Samsung Electronics are said to both be planning to release 12-inch tablets, and that Apple is currently cooperating with Quanta Computer on... Read more
Apple’s 2011 MacBook Pro Lineup Suffering Fro...
Appleinsider’s Shane Cole says that owners of early-2011 15-inch and 17-inch MacBook Pros are reporting issues with those models’ discrete AMD graphics processors, which in some cases results in the... Read more

Jobs Board

*Apple* Retail - Manager - Apple (United Sta...
Job SummaryKeeping an Apple Store thriving requires a diverse set of leadership skills, and as a Manager, youre a master of them all. In the stores fast-paced, dynamic Read more
*Apple* Support / *Apple* Technician / Mac...
Apple Support / Apple Technician / Mac Support / Mac Set up / Mac TechnicianMac Set up and Apple Support technicianThe person we are looking for will have worked Read more
Senior Mac / *Apple* Systems Engineer - 318...
318 Inc, a top provider of Apple solutions is seeking a new Senior Apple Systems Engineer to be based out of our Santa Monica, California location. We are a Read more
*Apple* Retail - Manager - Apple Inc. (Unite...
Job Summary Keeping an Apple Store thriving requires a diverse set of leadership skills, and as a Manager, you’re a master of them all. In the store’s fast-paced, Read more
*Apple* Solutions Consultant - Apple (United...
**Job Summary** Apple Solutions Consultant (ASC) - Retail Representatives Apple Solutions Consultants are trained by Apple on selling Apple -branded products Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.