• Recent
    • Unsolved
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login
    1. Home
    2. JJ Fullmer
    • Profile
    • Following 5
    • Followers 4
    • Topics 55
    • Posts 976
    • Groups 3

    JJ Fullmer

    @JJ Fullmer

    Testers

    Been using FOG since 2013.
    Powershell developer and enthusiast
    Avid Tester of new technologies with Fog.

    347
    Reputation
    4.6k
    Profile views
    976
    Posts
    4
    Followers
    5
    Following
    Joined
    Last Online
    Website github.com/darksidemilk
    Location Sandy UT

    JJ Fullmer Unfollow Follow
    FOG Hangouts Testers Moderator

    Best posts made by JJ Fullmer

    • Creating a csv host import from a network scan

      Run the following code in powershell (after editing it with your network’s subnets) to create a csv that will import all hosts on your network.

      # examples, just gotta put subnets minus the final .x in a string array
      # Could also be params if this was a function
      $subnets = @("192.168.1", "192.168.2", "10.2.114", "192.168.0"); 
      $subnets | ForEach-Object { # loop through each subnet
      	for ($i=0; $i -lt 255; $i++) { # loop through 0 to 255 of the subnet
      		$hn = nslookup "$_.$i"; # run nslookup on the current ip in the loop
      		if ($hn[3] -ne $null -AND $hn[3] -ne "") { # does the ip have a dns entry
      			$hostN = $hn[3].Replace("Name:","").Trim(); # parse the nslookup output into a fqdn host name
      			$mac = getMac /S $hostN; # does the hostname have a mac addr. Can also add /U and /P for user and password if not running from a administrative account
      			if ($mac -ne $null) { # was there a mac for the host?
      				$macAddr = $mac[3].Split(' ')[0]; # use the first found mac address and parse it
      				"$hostN,$macAddr" | Out-File C:\hosts.csv -Append -Encoding UTF8; # add the hostname,macaddress to the csv
      			}
      		}
      	}
      }
      
      posted in Tutorials
      JJ FullmerJ
      JJ Fullmer
    • RE: Can't Edit Exisiting Snapins or Create New ones

      @Arrowhead-IT Scratch that, it totally worked after a restart. So if you go breaking your permissions just run the script posted and restart and violia!

      posted in Bug Reports
      JJ FullmerJ
      JJ Fullmer
    • RE: New Inits

      Everything is working for me now! hooray for the new inits!

      posted in General
      JJ FullmerJ
      JJ Fullmer
    • RE: Cortana/Windows Search breaks in default profile

      @Lee-Rowlett I think you are somewhat correct there. In all my testing I found that it relates to when a user first logs in it installs all the metro apps for that user including cortana. And when you do a profile copy in the system advanced settings control panel it ends up copying some of those installed apps to the default profile which causes the installation of metro apps on a new profile to fail, but there’s no error because the installs think they succeed since the files are already there.
      At least I think that has some to do with it. My new script system seems to work flawlessly and it is much easier than my old way of having to change the registry everytime and such.

      I would still test your theory for you, just for funzies, but I don’t actually use an unattend.xml. I don’t like sysprep. It breaks my default profile sometimes, and I’ve seen it break other things and it forces you to go back to oobe which messes with my computer naming system. I’ve kinda found it to not be necessary. Yes it resets some security id’s for activation this and that but if you are using windows enterprise volume licensing, that doesn’t cause any problems. In windows 7 I figured out the registry key to change and then just re-inputting the windows key and reactivating gave it a new sid. Windows 8 and 10 just work without issue without doing that. As for drivers, I make my images on a vm so they’re already hardware independent and I use the terminal tool devcon (included in the windows wdk 8.1, I just copy the devcon.exe over to my image vm after installing the wdk on my workstation) to uninstall all the devices in the device manager before rebooting with devcon -r remove *
      It goes through the uninstalling of devices much much faster than sysprep does too.

      So thank you sir for your help, but I think I got it figured out.

      posted in Windows Problems
      JJ FullmerJ
      JJ Fullmer
    • Powershell API Module

      I created a powershell module for using the Fog API

      https://www.powershellgallery.com/packages/FogApi

      Install instructions are found at that link.

      You can also use powershellget https://www.powershellgallery.com/packages/PowerShellGet the command Install-Module -Name FogApi;*

      Importing that module will help you to set up a quick and easy and crossplatform way to manage fog from a powershell prompt.

      It is structured based on the api documentation found here https://news.fogproject.org/simplified-api-documentation/
      It even autocompletes the parameter options based on that documentation.

      So if you read that documentation and see that you can get an ‘object’ you can then take that to the command by saying Get-FogObject -type object -CoreObject objecttype that object type validates/autocompletes to the list of available core objects found in the documentation.

      If you install the module and run help Invoke-FogApi it will display a bit more verbose help and documentation on how it all works.

      There are a few main functions to use that all make calling the Invoke-FogApi function a bit easier with autocompletion fun times

      • For GET api calls : Get-FogObject
      • For POST api calls : New-FogObject
      • For PUT api calls : Update-FogObject
      • For DELETE api calls : Remove-FogObject

      Each of these return powershell objects. If you’re unfamiliar with powershell and powershell objects, then this is a good way to learn.
      They make it so you can take information and easily find and manipulate their properties.
      i.e. if you did a $hosts = Get-FogObject - type Object -CoreObject host $hosts would contain 2 properties, a count of returned objects and an array of all your fog hosts, each with all the information fog has on them. So lets say you want to see all your hosts that have a intel cpu, you can search all the hosts for where the inventory’s cpu manufacturer has ‘intel’ in its value. $intelPCs = $hosts.hosts | ? { $_.inventory.cpuman -match 'intel' } Then maybe you just want the hostids, names, and mac addresses. $intelPCList = $intelPCs | Select-Object id,name,primac; $intelPCList;

      PS Objects can also easily be turned into json by piping them into a ConvertTo-Json command. Meaning that you can just change the values of an object’s properties, such as a host’s name, image, etc. And then convert that to json to use as the jsondata in any other command.

      I also included a Install-FogService function in the module for good measure that downloads the latest version of the client msi installer from your server and then silently installs it. In theory, you could use Invoke-Command to run that command on remote computers (though you would also have to import the module on each computer).

      There is a settings.json file that the module pulls from to get your api keys and servername. It needs to be set manually, but automatically opens in an appropriate editor for your OS if it finds that the settings are still set to default. The default settings are explanations of where to find the values on your server.

      Help Info from function code Will be updated overtime, putting here as it is the help info uri listed in module manifest
      Invoke-FogApi

      <#
              .SYNOPSIS
                 a cmdlet function for making fogAPI calls via powershell
              
              .DESCRIPTION
                  Takes a few parameters with some pulled from settings.json and others are put in from the wrapper cmdlets
                  Makes a call to the api of a fog server and returns the results of the call
                  The returned value is an object that can then be easily filtered, processed,
                   and otherwise manipulated in poweshell.
                  The defaults for each setting explain how to find or a description of the property needed.
                  fogApiToken = "fog API token found at https://fog-server/fog/management/index.php?node=about&sub=settings under API System";
                  fogUserToken = "your fog user api token found in the user settings https://fog-server/fog/management/index.php?node=user&sub=list select your api enabled used and view the api tab";
                  fogServer = "your fog server hostname or ip address to be used for created the url used in api calls default is fog-server or fogServer";
                          
              .PARAMETER serverSettings
                  this variable pulls the values from settings.json and assigns the values to 
                  the associated params. The defaults explain how to get the needed settings
                  fogApiToken = "fog API token found at https://fog-server/fog/management/index.php?node=about&sub=settings under API System";
                  fogUserToken = "your fog user api token found in the user settings https://fog-server/fog/management/index.php?node=user&sub=list select your api enabled used and view the api tab";
                  fogServer = "your fog server hostname or ip address to be used for created the url used in api calls default is fog-server or fogServer";
      
              .PARAMETER fogApiToken
                  a string of your fogApiToken gotten from the fog web ui. 
                  this value is pulled from the settings.json file
              
              .PARAMETER fogUserToken
                 a string of your fog user token gotten from the fog web ui in the user section.
                 this value is pulled from the settings.json file
              
              .PARAMETER fogServer
                  The hostname or ip address of your fogserver, 
                  defaults to the default name fog-server
                  this value is pulled from the settings.json file
              
              .PARAMETER uriPath
                  Put in the path of the apicall that would follow http://fog-server/fog/
                  i.e. 'host/1234' would access the host with an id of 1234
                  This is filled by the wrapper commands using parameter validation to 
                  help ensure using the proper object names for the url 
                  
              .PARAMETER Method
                Defaults to 'Get' can also be Post, put, or delete, this param is handled better
                by the wrapper functions
                get is Get-fogObject
                post is New-fogObject
                delete is Remove-fogObject
                put is Update-fogObject
              
              .PARAMETER jsonData
                  The jsondata string for including data in the body of a request
              
              .EXAMPLE
                  #if you had the api tokens set as default values and wanted to get all hosts and info you could run this, assuming your fogserver is accessible on http://fog-server
                  Invoke-FogApi;
      
              .Example
                  #if your fogserver was named rawr and you wanted to put rename host 123 to meow
                  Invoke-FogApi -fogServer "rawr" -uriPath "host/123" -Method "Put" -jsonData "{ `"name`": meow }";
      
              .Link
                  https://news.fogproject.org/simplified-api-documentation/
              
              .NOTES
                  The online version of this help takes you to the fog project api help page
                  
          #>
      
      posted in Tutorials api api help powershell task management fogapi-psmodule
      JJ FullmerJ
      JJ Fullmer
    • RE: executing batch file from snapin

      I would suggest using the full path of the file in your batch script instead of changing the directory.
      And when I say full path, I mean the true full path, not the mounted S:\ drive.
      Even if S:\ is being mounted by active directory or is a mapped drive as part of your image, I would still suggest using the full network/unc path.
      I would also suggest mounting it with net use and a username and password. This will ensure the system account that the Fog Service uses has access to the files you want
      I would also add some logging and other error preventions.

      i.e. if S:\ was mapped to \FileServer\Share …

      @ECHO off
      
      echo. Create variables to make scripting easier
      set sharePath=\\FileServer\Share\Pat
      
      echo. Mount S drive path, replace username and password with share credentials. 
      echo. If share is public omit the /USER parameter and everything after it
      
      
      net use %sharePath% /USER:username password
      
      echo. make sure destination exists, create it if it doesn't
      if not exist C:\temp mkdir C:\temp
      
      echo. copy each file, add /Y to overwrite without any prompt
      echo. copying tdpunt...
      copy /Y %sharePath%\tdpunt.bat C:\temp\ > C:\temp\tdpunt-bat-Copy.log
      echo. copying tundpt.exe...
      copy /Y %sharePath%\tundpt.exe C:\temp\ > C:\temp\tundpt-exe-Copy.log
      
      echo. Done!
      
      exit
      
      

      Use that and then see if the .log files show up after deploying the snapin.

      Also, in the web gui snapin config, you should take out the /qn that does nothing.
      The snapin arguments section is for custom arguments that you have in your script. Your script doesn’t do anything with the /qn and it could cause issues. The /c parameter is passed to the cmd.exe command which tells cmd.exe to open a prompt, run the command, and then close.
      If you had a line in your script like this

      if "%1" == "/qn" (
          echo. hey look a parameter, lets do something since it's there!
      )
      

      then the /qn would have a point.

      Hope that helps a bit.

      Thanks,
      -JJ

      posted in General
      JJ FullmerJ
      JJ Fullmer
    • RE: Powershell API Module

      New Module Version Published

      Just wanted to let people know that there’s a new version of the API yay!
      It’s been published to the psgallery here https://www.powershellgallery.com/packages/FogApi/1903.0.0.22 and it is awaiting a pull request to show up in the fog community scripts git.
      It has new functions to help do some common tasks, particularly with snapins. Here’s a list of the current functions.

      Add-FogSnapins
      Set-FogObject
      Get-FogAssociatedSnapins
      Get-FogGroup
      Get-FogHost
      Get-FogHosts
      Get-FogInventory
      Get-FogLog
      Get-FogObject
      Get-FogServerSettings
      Get-FogSnapins
      Install-FogService
      Invoke-FogApi
      New-FogObject
      Remove-FogObject
      Remove-UsbMac
      Set-FogInventory
      Set-FogServerSettings
      Set-FogSnapins
      Start-FogSnapins
      Update-FogObject
      
      posted in Tutorials
      JJ FullmerJ
      JJ Fullmer
    • Automating Git Updates for FOG

      In the past I made a script for automating svn updates. Since sourceforge has been making a habit of crashing lately, I decided to start using the git repo instead and adjusted my script to work with git.
      I figured others might benefit from it so why not share…

      #!/bin/bash
      clear
      # -------------------------------------------
      # Fog Git Updater
      # -------------------------------------------
      # -------------------------------------------
      # Script Purpose
      # -------------------------------------------
      # This script is designed to run an automated update of the latest FOG Git dev build and it's cron friendly
      # -------------------------------------------
      # -------------------------------------------
      # Some prereqs for this script
      # -------------------------------------------
      # 1. Already have an existing working install/configuration of FOG 1.0 or later
      #
      # 2. Have git installed and setup. You can do that by doing....
      # 	sudo apt-get install git
      #  	mkdir /home/fog/fogInstalls/git
      #	git clone https://github.com/FOGProject/fogproject.git /home/fog/fogInstalls/git
      #
      # 3. A script to echo the encrypted version of your sudo password, create one with this function
      #	just put in your password into the following in place of your_super_secret_password (leave the quotes)
      #	and then uncomment and copy paste the function into a terminal and then run it with just the name of the function pw
      	# pw(){
      	# 	touch /home/fog/fogInstalls/.~
      	# 	ossl=`echo "your_super_secret_password" | openssl enc -des -a -e -pass pass:PASSWORD`
      	# 	echo 'echo "$(echo '$ossl' | openssl enc -des -a -d -pass pass:PASSWORD)"' >> /home/fog/fogInstalls/.~
      	# 	sudo chown fog.root /home/fog/fogInstalls/.~
      	# 	sudo chmod 700 /home/fog/fogInstalls/.~ 
      	# }
      # -------------------------------------------
      # -------------------------------------------
      # Variables
      # -------------------------------------------
      # -------------------------------------------
      echo "Creating Script variables..."
      fogInstalls='/home/fog/fogInstalls'
      gitPath="$fogInstalls/git"
      backup="$fogInstalls/backups"
      pw=`sh $fogInstalls/.~` 
      # -------------------------------------------
      # -------------------------------------------
      # Functions
      # -------------------------------------------
      # -------------------------------------------
      perms(){
      	sudo chmod -R 775 $1
      	sudo chown -R fog.fog $1
      }
      
      srvUpdate(){
      	# Enter sudo mode aand do some quick server maintenance update fun times
      	# First, enter sudo mode by echoing the output of decrypting your encrypted password and pipe that into an apt-get update
      	#	Don't worry, it doesn't output the password into the terminal
      	#	Now that the password is in once the terminal will keep it stored for the next bunch of sudo commands
      	echo "Running Sever updates!..."
      	echo $pw | sudo -S apt-get update -y
      	sudo apt-get upgrade -y # install any upgrades you just downloaded
      }
      
      backupConfig(){
      	# Backup custom config and other files
      	# Copy the latest versions of any files you've changed that will be overwritten by the update and backup the database just in case.
      	# For example you may want to back up...
      	# Config.php
      	# 	To be on the safe side your config file in the /opt folder that has may have a corrected webroot for ubuntu 14.04 and may have stored encrypted credentials (i.e mysql)
      	# 		I think that the installer uses this file and keeps it anyway, but I like to be careful
      	# Exports file
      	#	Because this runs the installer with a yes pipe, it ends up telling it that the image path is "y",
      	# 		simply backing up and restoring your current one avoids the issue of fog not finding your precious images. 
      	# Custom pxe boot background
      	# 	If you have a custom background for the pxe menu, the bg.png file
      	# Mysql database dump
      	#	It would be rather troublesome if something went horribly wrong in the update and your database goes kaboom, it's unlikely but backups are a good thing 
      	# Just a note, It's a good policy to also have backups of these outside of your server, which you could add to this script with an scp command or something like that
      	# -------------------------------------------
      	echo "make sure backup dir exists..."
      	if [ ! -d $backup ]; then
      		mkdir $backup
      	fi
      	echo "Dumping the database..."
      	mysqldump -u root --all-databases --events > $backup/DatabaseBeforeLastUpdate.sql #backup database
      	echo "Backing up config and custom files..."
      	echo "config.php..."
      	sudo cp /opt/fog/service/etc/config.php $backup/config.php
      	echo "fog settings..."
      	sudo cp /opt/fog/.fogsettings $backup/.fogsettings
      	echo "nfs exports..."
      	sudo cp /etc/exports $backup/exports
      	echo "custom pxe background..."
      	sudo cp /var/www/html/fog/service/ipxe/bg.png $backup/bg.png 
      }
      
      gitP(){
              perms $gitPath
      	echo "git pull...."
      	cd $gitPath
      	git pull
      }
      
      updateFOG(){
      	echo "running FOG installer..."
      	cd $gitPath/bin
      	sudo bash installfog.sh -Y
      }
      
      restoreConfig(){
      	# Restore backed up files
      	# Restore the backed up files to their proper places and make sure they're formatted correct too.
      	echo "restoring custom pxe background..."
      	sudo cp $backup/bg.png /var/www/html/fog/service/ipxe # Restore Custom Background 
      	# I found that I needed to do this in some configurations, but it may no longer be neccesarry...
      	echo "Creating undionly for iPxe boot in ipxe folder, just in case..." 
      	sudo cp /tftpboot/undionly.kpxe /tftpboot/undionly.0 # backup original then rename undionly 
      	sudo cp /tftpboot/undionly.0 /var/www/html/fog/service/ipxe/undionly.0
      	sudo cp /var/www/html/fog/service/ipxe/undionly.0 /var/www/html/fog/service/ipxe/undionly.kpxe
      }
      
      fixPerms(){
      	echo "Changing Permissions of webroot..."
      	perms '/var/www/html/fog'
      	echo "Changing permissions of images...."
      	perms '/images'
      	echo "Changing permissions of tftpboot...."
      	perms '/tftpboot'
      }
      
      # -------------------------------------------
      # -------------------------------------------
      # Run the script
      # -------------------------------------------
      # -------------------------------------------
      srvUpdate
      backupConfig
      gitP
      updateFOG
      restoreConfig
      fixPerms
      echo "Done!"
      
      posted in General
      JJ FullmerJ
      JJ Fullmer
    • RE: Active directory Join issue

      @anthonyglamis Fogcrypt is essentially obsolete, yes. You can still put the fogcrypt output into the legacy input but I find the new auto-encrypt to work better. But yes I’m pretty sure that the fogcrypt tool is still there

      I hadn’t noticed that the hashes were different before, so I checked mine and they are different. I haven’t had any problems though, so I would say it shouldn’t be an issue.

      posted in Windows Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: HP Z640 - NVME PCI-E Drive

      I just finished working with @Tom-Elliott we got it working. It was a simple fix.
      It’s in the latest fog update now. So nvme drives work with fog 100% now right out of the box. Awesome like a possum!

      posted in Hardware Compatibility
      JJ FullmerJ
      JJ Fullmer

    Latest posts made by JJ Fullmer

    • RE: FOG Secure Boot with Shim

      @jmeyer I have some e16 g1s and I am not having the same issue. What version of fog are you running? Are there any other secure boot settings you have configured or maybe not configured? Can you get to the mok enroll with secure boot off? And then turn it back on?

      posted in Tutorials
      JJ FullmerJ
      JJ Fullmer
    • RE: PXE does not load in EFI mode.

      @azm9s actually reading the claude output looks like you’re actually pointing to secureboot/ipxe.efi for option 67. Switch that to either secureboot/snponly-shimx64.efi or secureboot/ipxe-shimx64.efi and that may do the trick

      posted in General Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: PXE does not load in EFI mode.

      @azm9s I asked Claude for help, it found some stuff

      @azm9s Good news buried in your tcpdump: DHCP is working perfectly. Discover → Offer → Request → ACK, the client takes 192.168.65.243, and ARCH (93) = 7 means the firmware is correctly identifying itself as x64 UEFI. Your Realtek 8111H, the board’s UEFI network stack, and IPv4 PXE are all fine. Whatever is broken happens after DHCP.

      That reframes the problem — you’re not stuck at “PXE won’t start,” you’re stuck at “NBP won’t load or won’t run.”

      First: we’re blind to the actual failure

      Your filter is port 67 or port 68, so the capture cannot show TFTP. Please re-run on the FOG server (192.168.65.35) with:

      tcpdump -i eth0 -e -n -vv ether host fc:9d:05:76:7c:00
      

      That one change decides everything:

      • No TFTP RRQ at all → the firmware never got past DHCP (see option 60 below)
      • RRQ answered with error code 1, File not found → wrong path
      • RRQ, full successful transfer, then a blank screen → Secure Boot is rejecting the binary

      Also confirm where you ran the original capture — if it wasn’t on .35, you’d never see the unicast TFTP anyway.

      The boot file almost certainly doesn’t exist

      DHCP is handing out secureboot/ipxe.efi, but your /tftpboot listing has no secureboot/ directory in it, and no such file. FOG doesn’t ship a secureboot/ipxe.efi under any version — on 1.6 the signed binaries are secureboot/snponly-shimx64.efi and secureboot/ipxe-shimx64.efi.

      Check both of these on the server:

      ls -la /tftpboot/secureboot/
      tftp 192.168.65.35 -c get secureboot/ipxe.efi
      

      If that tftp get fails, there’s your answer. Point option 67 at snponly.efi (a file you’ve confirmed exists) purely as a test.

      Your DHCP server is sending option 60 = PXEClient

      Vendor-Class (60), length 10: "PXEClient"
      

      This is the old WDS-on-the-same-box workaround, and it can actively break plain TFTP boot. Per the PXE spec, option 60 in the offer tells the client “I am a PXE boot service” — so instead of just using siaddr + boot filename, the client starts looking for option 43 boot-server sub-options and may try ProxyDHCP on port 4011. There’s no option 43 in your offer, so some UEFI implementations simply stall right here, which is exactly what you’re seeing.

      Unless WDS is genuinely running on 192.168.65.11, delete option 60 from your scope/server options and retest.

      Minor related note: Windows DHCP null-terminates its string options, which is why tcpdump shows "secureboot/ipxe.efi^@". Usually harmless, but if you get the TFTP capture, glance at the RRQ filename for a stray byte.

      (The doubled Offer and ACK in your capture are the same packet seen twice — identical IP IDs. Not a second DHCP server, ignore it.)

      Motherboard: MS-7C96, MSI Click BIOS 5

      First, your “UEFI cannot be disabled” is expected behavior, not a fault. MSI greys out / force-locks CSM when Secure Boot is enabled, and also when the installed GPU (including a Ryzen APU’s iGPU) has no legacy VBIOS. Since your client is correctly requesting arch 7, UEFI is what we want — don’t chase legacy mode.

      Press Del, then F7 to get into Advanced mode — EZ mode hides all of the following, and it’s the usual reason people report options as missing.

      Settings → Advanced → Windows OS Configuration

      • Secure Boot → Secure Boot Support: Disabled
      • If that’s greyed out: Secure Boot → Key Management → set Factory Default Key Provisioning: Disabled, or delete/clear all keys to put the board in Setup Mode. Secure Boot is always disableable on this board — Tom is right that it would be a firmware bug otherwise.
      • BIOS UEFI/CSM Mode lives here too, which is where you saw UEFI locked.

      Settings → Boot

      • MSI Fast Boot: Disabled
      • Fast Boot: Disabled

      MSI Fast Boot skips USB and network initialization outright. It’s a common cause of erratic PXE on these boards and is worth turning off regardless.

      Settings → Advanced → Integrated Peripherals

      • LAN Option ROM: Enabled
      • Network Stack (may be its own menu entry depending on BIOS revision): Ipv4 PXE Support: Enabled, Ipv6 PXE Support: Disabled

      Flash the latest BIOS via M-FLASH (FAT32 USB stick). MS-7C96 has been through a lot of AGESA revisions and several MSI 500-series releases shipped with a broken Realtek UEFI PXE driver. This is a genuinely common fix for “DHCP completes, NBP never downloads.”

      About that MAC address on screen

      Start PXE over IPv4 on MAC address: 00-00-00-00-00-00 — did you redact that, or is it literally printing zeros? The wire shows a real MAC (fc:9d:05:76:7c:00) doing valid DHCP, so the two don’t agree. If the screen genuinely shows all zeros, that points at the Realtek LAN EEPROM not being read at ROM init time — CMOS clear plus a BIOS reflash. A photo of the screen would settle it.

      Realtek 8111H, snponly vs ipxe

      When you get to the point of testing binaries, try snponly.efi and ipxe.efi and note which behaves differently. snponly.efi uses the firmware’s own SNP/UNDI driver; ipxe.efi uses iPXE’s native driver. FOG 1.6 standardized on the snponly builds specifically because they’re more reliable on modern UEFI firmware. If snponly fails but ipxe works, the board’s SNP implementation is the culprit and that’s useful information.

      Version, and the “customized” question

      Still need to know what version you’re on — your /tftpboot listing looks like 1.5.x. And when you say customized: if you mean you’ve used FOG’s supported customization points (https://docs.fogproject.org/supported-customizations), we can help fine. If you mean you forked it at some snapshot and changed internals, we can still help with the DHCP/BIOS side above, but anything server-side is going to be guesswork on our end.

      Either way, working-1.6 is worth a look here — it has proper Secure Boot support with Microsoft-signed shim chains and a local ESP boot option that’s built for testing exactly this kind of stubborn hardware:

      • https://docs.fogproject.org/install-fog-server
      • https://docs.fogproject.org/local-esp-boot

      Start with the TFTP capture though. That’ll tell us which of the three branches above we’re actually in, and we’ll stop guessing.

      posted in General Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: PXE does not load in EFI mode.

      @azm9s also, silly question, but is this a problem just with this motherboard? Other devices pxe boot fine?

      posted in General Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: PXE does not load in EFI mode.

      @azm9s echoing the question if what version you’re on?
      Also the pxe saying 0s for the mac points to a mobo option, maybe dhcp has to be turned on in the mobo under pxe or network devices? Maybe it isn’t saving that setting? I’m guessing with no uefi disable you mean there’s no bios/legacy/csm option to use the legacy boot files?
      I would suggest trying out working-1.6. There’s a lot of new options for pxe including secure boot support and local pxe boot environment zip downloads for testing trouble hardware like this
      https://docs.fogproject.org/install-fog-server
      https://docs.fogproject.org/local-esp-boot

      Also as far as customized goes, there are lots of supported customizations that don’t get overwritten on updates https://docs.fogproject.org/supported-customizations

      posted in General Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: FOG 1.6.0-beta.2644 DHCP

      @jmeyer Would you be willing/able to try again without bypassing it to help confirm the fix?
      @rogersk4132 thank you for testing and confirming!

      posted in FOG Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: Group Multicast - Dev-Branch

      @edvandro Thank you for reporting. We’re working on a fix for that right now.
      I would also suggest trying working-1.6 instead of dev-branch as we have a lot of new improvements and are anxious to get feedback. I’ve been running the 1.6 “beta” as my production fog server for a few years now and recently we’ve added a lot of new long-requested features.

      posted in FOG Problems
      JJ FullmerJ
      JJ Fullmer
    • RE: How to upgrade to FOG 1.6?

      @Valer
      @Tom-Elliott may have already fixed this, but if you’re using refined that would also need to be signed. We should be able to just have it signed by our new secure boot system and then it should be happy.
      But also, the newer version of ipxe has proper support for SANBOOT in uefi mode, so you may be able to skip over refined and just use SANBOOT to boot to disk, try SANBOOT as the exit mode on a host and see if works, if it does you can change your global default and have an easier time.

      posted in General
      JJ FullmerJ
      JJ Fullmer
    • RE: How to upgrade to FOG 1.6?

      @Tom-Elliott said in How to upgrade to FOG 1.6?:

      Client state What the task does
      Setup Mode (platform key cleared) Enrols outright. Nothing to confirm, nobody at the keyboard.
      Normal (keys present, Secure Boot off) FOS stages the MOK request itself, non-interactively. Someone answers the blue MokManager screen once on the next reboot.
      Already enforcing Secure Boot Cannot run — the machine will not boot FOS in the first place. Use the live USB route for those.

      One minor correction, with secure boot enabled on a new machine, if you boot to the signed shim you can use the Mok enrollment boot issue without needing to disable secure boot, but you do have to be physically at each machine to enroll.

      posted in General
      JJ FullmerJ
      JJ Fullmer
    • RE: Surface Laptop 7th Edition - PXE loads and then immediately reboot's

      @csurepair I think Elite is referencing snapdragon elite? I actually don’t see any intel options for the laptop 7.
      So you may need it to boot to the arm pxe file, but you’ll also need a new image for arm64 I imagine.
      Microsoft also did something like this with the surface GO for business, there was a surface go 4 but all of a sudden no more surface go 4 being made and the product line was dead. They made a similarly priced (at the time, not anymore) 12" surface tablet but snapdragon based. We opted to not change our entire cpu architecture, so sadly I don’t have any experience with getting this working. I know @rodluz has done a lot with getting arm working with FOG and may be of more help if booting to arm kernel and init doesn’t work.

      posted in Hardware Compatibility
      JJ FullmerJ
      JJ Fullmer