Problems inporting VeriSign certificates Question: I am trying to import a VeriSign cert using the steps in TID 10089761. When I paste in the cert and click Answer: Did you look at TID10055757.and follow the steps there? That TID seems to describe your problem exactly, so I think it'd be worth a shot. Minimun rights to set user space restrictions Question: What are the minimum eDirectory rights (on Server and Volume objects) to change user space restrictions on a volume? Answer: TFS - Supervisor to the volume; NSS, Supervisor to the server Problems with in-place upgrade Question: I'm trying to do in-place upgrade from eDirectory 8.71 to 8.73 on NW 5.1 (SP7) via NWCONFIG (install product not listed). I begin the file copy and everything is normal so far. I have 2.82 GB free on SYS, so it's not like I'm running out of disk space. The file copy stops with: "an error occurred: Select an action:" I get 4 options, which are: 1) Retry copy 2) Force reconnect and try copy again 3) Skip file and copy next file 4) Abort copying. The only option that works is to abort, and then I'm back to square one. I've remmed out everything in autoexec except bare essentials, before starting the upgrade. I've run DSRepair and DS Health looks fine. I'm using JVM 1.31, which is current enough. What could be wrong? I did this same in-place upgrade on my two NW 6.5 servers, no problem. Answer: Maybe the install files are corrupted, or the CD is scratched. If this suggestion doesn't work, downlaod purge_nw.exe and run that against the server. Also Go into Monitor - server parameters - NCP and Set Client File Caching = Off, and Set Level 2 OpLocks Enabled = Off. Adding the class to all user accounts Question: How do you add the class to all your existing user accounts? We are adding classes for MacOSX Home Directory attributes to all our users, and I am trying to find the best way to update all the current user accounts (about 30,000). We have an SQL Database that has all the User info in it, and we are currently using JRBUtils to create/modify user objects via scripts. However, I now need to extend all the user objects that are currently there and extend any new accounts we create and push through the new fields and values to each user. How are other people doing this? Answer: Export all users via LDAP. You just need the DN attribute. Search and replace, or use your favorite text hacking tool(s) to add these lines to the file: Question: I need a way to export user information from a database. All I need is the first name, last name and e-mail address. I am trying to do an LDIF export through ConsoleOne but I am clueless. I can do an all-user-attributes export, but that is just a mess. I don't know how to filter it so that I just get the needed information. Can anyone help? Answer: Go to the screen "Set Search Criteria" in COnsoleOne. At the "filter" tab you fill in "objectclass = user". At the Attribute List you add attributes such as givenname,fullname, mail and sn. Question: We have three divisions, connected via VPN, in the same Tree but different containers. Bill's user object is in CITY-1. When he logs in (in City 1) he logs in in the CITY-1 context, and executes the system login script. But he also needs, from time to time, to connect to a Terminal Server in City 3 and log in through its Novell client and execute City 3's system login script. (in the CITY-3 context for the Terminal Server session). I don't want to create duplicate user objects in both containers, because unexpected results occur when user objects are not unique. Is there a relatively simply way I can achieve this, without creating two different user objects for the same user? Answer: Google for "contextless login" and you'll find lots of possibilities. You can also install the Novell Client 4.9. and configure LDAP-based contextless login. Question: Anyone know where to find a good writeup or book on setting up CheckPoint to authenticate users with eDir/Ldap? Answer: If you do a search in the Knowledgebase for "checkpoint ldap" you can find these TIDs ... Seeing other servers in a tree Question: In a tree, must all servers be able to see or have full access to all other servers in that tree? Answer: No, but all servers in the same partition must. Or even more precisely, with current eDirectory versions, at the very least the master of one partition must be able to communicate with all servers having a replica of that partition and vice versa. |
|||||||||||||||||||||||||||||||||||||||||||||
![]() |