This Readme contains information regarding issues that affect the installation and usage of Novell® Open Enterprise Server (OES) Support Pack 2.
This document contains only a list of issues. For information on all of the features and components in Open Enterprise Server, see the Novell Open Enterprise Server Web site.
For planning and information, see the Novell
OES SP2 Planning and Implementation Guide
.
For complete information on setting up and using OES, see the Novell Open Enterprise Server online documentation.
In this documentation, a greater-than symbol (>) is used to separate actions within a step and items within a cross-reference path.
A trademark symbol (®, ™, etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark.
When a single pathname can be written with a backslash for some platforms or a forward slash for other platforms, the pathname is presented with a backslash. Users of platforms that require a forward slash, such as UNIX* or Linux*, should use forward slashes as required by your software.
We want to hear your comments and suggestions about this manual and the other documentation included with OES. To contact us, use the User Comments feature at the bottom of any page in the online documentation.
This section contains information regarding general issues for Novell® Open Enterprise Server (OES) Support Pack 2 (SP2). For information about issues for specific components, see the sections pertaining to those components.
This document contains only a list of issues at the time OES Support Pack 2 released. For information on all of the features and components in Open Enterprise Server, please see the Novell Open Enterprise Server Web site or the Novell Open Enterprise Server online documentation. This document contains only a list of issues at the time OES Support Pack 2 released.
For a list of software fixes included in Support Pack 2, see the Open Enterprise Server Support Pack 2 List of Fixes. To view fixes included in NetWare 6.5 Support Pack 6, see NetWare 6.5 Support Pack 6 List of Fixes
Open Enterprise Server consists of two server platforms, SUSE® LINUX Enterprise Server 9 (SLES 9) with Support Pack 2 and NetWare®, as well as services that run on those server platforms.
OES SP2 is supported only on SUSE LINUX Enterprise Server 9 for x86 SP2, included with OES. There is no direct upgrade path from Novell Nterprise™ Linux Services 1.0.
Installing OES Support Pack 2 for NetWare is the same as installing NetWare 6.5 with Support Pack 5. The codebase of OES Support Pack 2 and NetWare 6.5 Support Pack 5 are the same. You can upgrade to OES from previous versions of NetWare. Upgrading to OES on NetWare is essentially the same as upgrading from previous versions of NetWare to NetWare 6.5 SP5 and OES SP2 for NetWare. Unless otherwise noted, all previously available functionality of NetWare 6.5 still works.
This section contains information about issues that affect the general operation of OES after it is installed and initially configured. Other component-specific issues are noted in the Readme sections for those components.
Some problems might occur when accessing an OES server from a Windows* XP client with SP2 installed. For example, a pop-up might appear, saying that the publisher is unknown. Please report to Novell any additional problems that occur.
If you want to create a new eDirectory™ tree that contains both NetWare and Linux servers, you must start the tree creation using a NetWare server first.If you use a Linux server to create a new tree and subsequently add a NetWare server to it, you will not be able to install any client or server licenses. Any features that require either a NetWare Server license and/or Novell Client™ Access license will be inaccessible.For more information, see Adding a NetWare Server to an OES Linux Tree in the Novell OES SP2 Planning and Implementation Guide.
The following issues exist on OES Linux:
Do not use the passwd utility to change the password for Linux User Management (LUM)-enabled users. To change the password for those users, use iManager or namusermod.
Do not use the pure-FTP service. Use vsftp instead.
If your OES Linux server occasionally freezes up, it could be caused by powersaved. To resolve this, disable powersaved by completing the following:
In YaST, select System > Runlevel editor > Powersaved
Click Disable > OK.
Click Finish to exit the Runlevel editor, then OK to exit YaST.
To disable kpowersave from displaying reminder messages and from loading at start up:
From the KDE desktop, right-click the kpowersave icon in the menu bar.
Click Quit, and then select to not have kpowersave loaded at startup.
As you plan to install and implement OES, be sure to leverage
the information in the Novell
OES SP2 Planning and Implementation Guide, especially
in Implementation
Caveats
and Installation/Upgrade/Migration
Caveats
.
This section contains issues for NetWare® 6.5 Support Pack 6. Issues from previous Support Packs are in the OES Support Pack 2 Readme.
In addition to software fixes, enhancements have been made to some of the components in NetWare 6.5 Support Pack 6. See the What’s New sections in the following administration guides:
To view fixes included in NetWare 6.5 Support Pack 6, see NetWare 6.5 Support Pack 6 List of Fixes.
A free update to Novell® Audit 2.0.2 is available separately at Novell Downloads. If you are using Novell Audit, you should download and install Novell Audit 2.0.2 Starter Pack. Updates to Novell Audit 1.0x are included in the Support Pack, but Novell Audit 1.0x is not included in the Overlay install.
NWConfig has the ability to run installation scripts that include logging in to servers. Previously, NWConfig has uppercased passwords before passing them on to authentication. To be compatible with Novell’s future direction with case-sensitive passwords, this has been changed. We have seen a few issues in our testing when bindery logins are attempted. We have not seen any issues when the user and context are included, resulting in a directory login. If you are using bindery logins, this could be an issue.
A new option has been added to scrsaver.nlm to support Universal Password. If you enable Universal Password and you also use scrsaver.nlm, you need to set the Universal Password option to Yes so that you can unlock your screen saver.
Table 2-1 Option Values for Universal Password
|
Value |
Description |
|---|---|
|
No |
(Default) The password is uppercased. |
|
Yes |
Password case is not changed. |
For more information, see TID 10101057.
If iManager 2.5 is installed on the NetWare server and you apply Support Pack 6, iManager and its plug-ins are automatically upgraded to version 2.6. For more information about iManager 2.6, see the iManager 2.6 Documentation.
If you are using iManager 2.02, iManager is not upgraded.
If you are already using iManager 2.6, no updates are installed, including plug-ins.
For more information about iManager 2.6 install scenarios with NetWare 6.5 Support Pack 6, see TID 3968737.
Beginning with NetWare 6.5 Support Pack 5, security was increased. If you are running tests using the Web Bench client that supports weak security, you might receive an error. To lower the server’s security so you can use Web Bench, see TID2974359.
For more information about the latest changes to config.nlm, see TID 2974476.
If you are updating Virtual Office or iManager by applying the Support Pack, you might receive a 500 error when Virtual Office or iManager loads the first time. Restarting Tomcat resolves the issue.
To restart Tomcat:
At the system console, enter tc4stop.
To start Tomcat, enter tomcat4.
You should wait about 30 seconds after stopping Tomcat before starting it again.
To see the two Tomcat classes running, enter java -show.
To avoid Java out-of-memory issues with Virtual Office and iManager, you can increase the memory allocated by editing the sys:\tomcat\4\tomcat4.ncf and increase the -Xmx256m setting up to -Xmx512. Then restart Tomcat.
In NetWare 6.5 SP6, support for keyboard polling has been added to enable NetWare to run on newer machines that do not have a legacy PS/2 keyboard port. This enables NetWare to be installed and to run before the USB keyboard drivers are loaded.
NetWare 6.5 SP6 contains changes to the default values for the Start and End dates for Daylight Saving Time for those time zones affected by the change. Effective starting in 2007, Daylight Saving Time starts on the second Sunday in March and ends on the first Sunday in November.
These new settings will be in place for any new server installed using the NetWare 6.5 SP6 overlay CDs. They are applied only if you select a time zone that is adopting the new start and end dates.
Applying SP6 to an existing NetWare 6.5 server does not make any changes to the Daylight Saving Time start and end dates. A separate utility, DSTshift, is available in \tools of the Support Pack and on the Support Web site. The utility is also available on support.novell.com. See the readme.txt file for more information about using the utility.
The DSTshift utility automatically adjusts the start and end dates for Daylight Saving Time on existing NetWare 4.x, 5.x, and 6.x servers. You can also adjust the settings manually at the server console and by editing the autoexec.ncf file.
If your server is running NetWare 6.5 Support Pack 5 with eDirectory™ 8.8 SP1 installed, you should apply the edir881ftf_1.exe patch prior to applying the Support Pack to prevent the Support Pack install from hanging.
If you did not apply the patch before installing the Support Pack and the installation hangs, apply the patch and rerun the NetWare Support Pack install.
You can also copy the dhost.nlm file from the /tools/edir88 directory of the Support Pack to the server's sys:\system directory and reboot the server before applying the Support Pack.
If your server is running NetWare 6.5 Support Pack 5 or earlier and you also want to upgrade the server to eDirectory 8.8 SP1, you should first apply NetWare 6.5 Support Pack 6 and then apply eDirectory 8.8 SP1. eDirectory 8.8 SP1 downgrades several security modules in NetWare 6.5 SP6; therefore, you should download and apply the latest Security Services update.
If post-installing products with eDirectory 8.8, you should deselect Certificate Server and NMAS products so these do not get downgraded. The local post-install warns you about this, but a remote post-install does not.
Beginning with NetWare 6.5 Support Pack 6, changes were implemented for Pervasive* to resolve an abend in BTCPCOM during Nessus* scans. For more information, see TID 3174344.
Unloading iSCSI while snapshots are active causes the server to stop responding. To avoid this, deactivate snapshots before unloading iSCSI.
If you apply NetWare 6.5 Support Pack 6 to a server already running Novell BorderManager® 3.8 Support Pack 5, filtserv.nlm is downgraded. To resolve this, manually copy the filtserv.nlm from the sys\system directory in the Novell BorderManager 3.8 Support Pack 5 to the server's sys:\system directory. The correct filtserv.nlm file is version 1.61.13, dated Thursday, November 24, 2005.
If you are using nwdeploy.exe to do a remote upgrade, and if Tomcat does not load after rebooting and iManager won't run, the catalina.jar file has become corrupted. To resolve this, copy the catalina.jar file from \products\tomcat4\tomcat4.zip on the overlay ISO path to the server’s \tomcat\4\server\lib directory.
To prevent this in future remote upgrades, unload Tomcat and unload Java prior to doing the upgrade by completing the following:
At the server console, enter: tc4stop.ncf admsrvdn.ncf to
To unload JAVA, cut and paste the following items into an NCF file named javadown.ncf : Console 'unload silvermasterinit',1 Console 'stopx',10 Console 'unload UCS2JAVA', 1 Console 'unload XFSVGA', 1 Console 'unload XFVGA16', 1 Console 'java -shutdownall',10 Console 'java -killall', 5 Console 'unload java ', 1 Console 'java -exit', 1
Doing a remote post-install of Certificate Server using the Deployment Manager may not complete the installation from the Supoort Pack 6 overlay. Since Certificate Server is installed by default in most cases, you should not need to post-install it again.
If Certificate Server needs to be post-installed such as when migrating server to new hardware, you should post-install Certificate server using the local server’s gui.
If printer agents come up in a Not Bound state, you need to load netdb.nlm by completing the following.
Unload ndpsm.nlm.
Load netdb.nlm.
load ndpsm.nlm.
For SSL private key files, file type Der is not supported.
Do not include spaces in filenames for public key certificate, private key, and trusted certificate files.
Certificates with more than one CA signer in the certificate chain are not supported. Use certificates having a single CA signer.
The following are issues when applying the Support Pack to Novell Branch Office (NBO).
If the install detects a Branch Office appliance, no files on the C: drive are backed up during the install. This change was made to prevent the appliance from running out of disk space on that drive.
Ongoing issues from earlier releases are available in the Novell Nterprise Branch Office 2.0.5 Readme.
If you continue to receive error -10 and error -30, even after following suggetions in section 2.2 of the NBO 2.0.5 Readme, and you have large Data sets to replicate, try the following:
On Novell Branch Office, set replication timeout=10000.
On the Corporate side, use Novell Remote Manager and increase the timeout for the branch from the default of 3600 to 10000.
Stop processors (on both Corporate and Branch Office) and set auto start processors=off so that on your next reboot, you are running with only one processor.
Have only one NIC enabled on both the Corporate and Branch Office.
After installing NW65SP6 on a Novel Branch Office server with IDE drives, the server might hang after rebooting. To resolve this, copy the ideata.ham and ideata.ddi files from the Support Pack’s \tools directory to the servers c:\nwserver\drivers directory.
This section contains issues for Open Enterprise Server (OES) Support Pack 2. Issues from Support Pack 1 and the initial release are listed in the individual product sections.
The following issues exist on OES Linux:
Open Enterprise Server Support Pack 2 includes updates for eDirectory 8.73. If you want to deploy eDirectory 8.8, see “Using YaST to Install and Configure eDirectory 8.8” in the Novell eDirectory 8.8 Installation Guide and TID 10100450 for known issues.
After applying SP2 patches, you need to do additional configuration
for several components as outlined in Configuring
Services After Applying an OES Support Pack
of the OES
Linux Installation Guide.
The Virtual Office component and updates are not included in Open Enterprise Server Support Pack 2. Existing Virtual Office installations will continue to run on servers updated to OES SP2. If you are creating a new server and want to install Virtual Office, install it using the Open Enterprise Server SP 1 CDs, then update or patch the server to SP 2.
To obtain the Virtual Office 1.6.1 for Linux update, download vo_linux1_6_1.tar.gz from the support.novell.com.
For NSS on Linux, I/O through an NSS software RAID 5 device on some SATA drives might be so slow that the machine appears to hang. Only certain SATA drives experience this I/O slowdown when used in RAID 5; other SATA drives perform as expected. We are not aware of any problems for NSS software RAID 0 or RAID 1 devices on SATA drives.
We are currently working to address this issue. Meanwhile, we recommend that you conduct a small I/O test prior to implementing NSS software RAID 5 on your SATA drives.
If you patch a server running Novell® SecretStore™ to OES SP2, SecretStore stops functioning because the configuration files were overwritten by the patches. To resolve this, you must reconfigure SecretStore using the following commands:
/usr/sbin/ssscfg -d
/secretstore_download_path/ss-uninstall
/secretstore_download_path/ss-install
/usr/sbin/ssscfg -c
Figure 3-1 Multi-byte Example

If you migrate data contained in NetWare NSS volumes to an OES Linux NSS volume, some characters of half width and full width cannot be in the same directory. Only one file is in a directory, and the other file is lost.
To avoid this, change filenames that have the same conditions as above before migrating from NetWare NSS to OES Linux NSS volumes.
Figure 3-2 Login Command Example

Instead, you should use ConsoleOne® to create login scripts using multi-byte characters. You can also use the Novell Client32™ to edit the user login script, which is accessed from the red N menu on the client.
Before installing exteNd v5.2.1, you must disable the Name Services Cache Daemon (nscd) on OES SP2 before the exteNd suite install. The daemon can be disabled in > > . The nscd service should be enabled after the exteNd suite install is completed.
This does not affect updating servers that already have exteNd Director already installed.
To add the schema extension for exteNd v5.2., you need to use a version of iManager from OES SP1 or earlier, ConsoleOne or the command line version of ICE1 schema extension. You can build the ICE command in iManager, and then cut and paste it to the command line in Linux and extend the schema that way.
GroupWise® cannot use the updated glibc that is included with OES SP2; if you install it, you receive errors that the POA cannot connect to the MTA via IP.
To resolve this, do not update the glibc package. If you have already installed the new package, you can backrev to the previous version by doing the following:
In YaST2, select
Select the drop-down menu, then choose .
From the list on the right, select , then click .
This lets you use the original CDs to backrev to the previous package.
Applying any of the current GroupWise 7 SP1 Field Test patches or beta, allows the GroupWise agents to run as root. After the application of the GroupWise patch files, it is no longer necessary to backrev the glibc patch
NSS software RAID 5 is not supported with clustering on OES Linux. NSS does support software RAID 5 if the disk is not shared in a cluster.
The following issues exist on OES Linux:
Open Enterprise Server Support Pack 2 includes updates for eDirectory 8.73. If you want to deploy eDirectory 8.8, see TID 10100450 for known issues.
If sys:\etc\resolv.cfg is not accessible, then both inetcfg.nlm and the option in Novell Remote Manager for NetWare do not show any domain names and name servers.
The Virtual Office component and updates are not included in Open Enterprise Server Support Pack 2. Existing Virtual Office installations will continue to run on servers updated to OES SP2. If you are creating a new server and want to install Virtual Office, install it using the Open Enterprise Server SP 1 CDs, then update or patch the server to SP 2.
To obtain the Virtual Office 1.6.1 for NetWare update, download vo_netware1_6_1.exe from support.novell.com.
The server health item for Available Memory in Novell Remote Manager for NetWare is configured by default with threshold values calculated as a percentage of the total server memory. Starting with OES SP2, adjustments have been made to the server's memory handling that allow for lower values for these thresholds, so the defaults for Suspect and Critical levels have been changed.
These changes to the default threshold values are in place on a new server install with OES SP2 (NW6.5 SP5), but the defaults are not automatically changed on a server that is being upgraded to the latest Support Pack, to avoid overwriting any custom values you have already set for these thresholds.
If you see the Available Memory server health item showing a status of Suspect (yellow) or Critical (red) after applying the Support Pack (that might not occur depending on the server memory and existing settings), adjust the threshold values to the new defaults for Available Memory.
In Novell Remote Manager, click under the heading.
Click > A > > .
The CE1000 LAN Driver has been removed from this support pack and replaced with the E1000 LAN Driver. If you install using the overlay (CD Image) method, the replacement E1000 driver is used automatically.
If you install using the support pack script install (using nwconfig.nlm), the old CE1000 LAN driver on the server is used. To run the new driver, run inetcfg to configure the new driver, or edit the autoexec.ncf file if you load Lan drivers from autoexec.ncf.
When using the Server Consolidation Migration Toolkit to move printers from one NetWare server to another, you might see the following error message:
Dropped printer agent is invalid. It has either been deleted, been disassociated with PSM, the source PSM no longer exists or the destination PSM no longer exists. Do you want to delete this object from the project database?
Click either or because the printer agent was already moved to a target PSM. Refreshing the objects shows that the move was completed.
It is not possible to set a time stamp on a subdirectory or file, from a directory that has white-space characters in its name. To resolve this, specify the absolute path of file or directory in quotes. This can also be done from the parent directory that doesn't have spaces in its name, then you can set the time stamp for the files or directories with the relative path specified in quotes.
Before installing this Support Pack on a Novell Branch Office (NBO) server, delete any previous backups on c:\nwserver\backspx, where x can be 2 to 4. This prevents the server from running out of disk space on the c: drive during the Support Pack installation, which could cause an abend.
This section describes issues related to the integrated installation of Novell® Open Enterprise Server SP2 (OES) for Linux and SLES 9 SP3.
For complete instructions on installing OES for Linux, see the OES Linux File and Data Locations.
You have the option of doing a new installation or upgrading an existing SLES 9, SLES 9 SP1, SLES 9 SP2 server to OES for Linux SP1.
For detailed installation information, see the OES Linux File and Data Locations.
This section contains the known installation issues for OES SP2 for Linux release.
Beginning with OES SP1, the Tomcat certificate file for cacerts was changed to /var/opt/novell/tomcat4/conf/cacerts. This change might affect services running inside Tomcat that make a connection to an SSL-enabled service and in multiple server configurations or for signed certificates obtained from a third-party.
Before applying the Support Pack, you should back up your the cacerts file in /usr/lib/SunJava2-1.4.2/jre/lib/security as described in TID 10098127.
If installing OES sp2, the internet connection test and downloading of release notes might fail and the YaST online update is populated with the wrong server. To resolve this issue, go to the Yast Online Update screen. Change the Installation Source to "User-Defined Location" and enter http://update.novell.com/YOU as the server. You should now be able to connect to the YaST online update server.
If this fails, check that you have DNS setup on your network. Currently there are no YOU patches available for the install so this step can be skipped.
The NetWare® server platform for Novell® Open Enterprise Server (OES) Support Pack 2 (SP2) is NetWare 6.5 with Support Pack 5 (SP5).
NetWare 6.5 SP5 and OES SP2 on NetWare are the same. Installing OES SP2 on NetWare is the same as installing NetWare 6.5 with Support Pack 5. Applying the NetWare 6.5 SP5 update is the same as upgrading to OES on NetWare; therefore, they both use the same CD set. ISO images of the NetWare 6.5 SP5 Operating System overlay CD and the NetWare 6.5 SP5 Products overlay CD are included with the Open Enterprise Server software, along with an ISO for the SP5 update CD.
For complete instructions on installing and upgrading to OES for NetWare, see the OES for NetWare Installation Guide.
This section lists new and enhanced features in this release of OES SP1 and later.
Novell no longer distinguishes between a NetWare 6.5 Support Pack installation and the OES for NetWare installation. The ability to choose between Open Enterprise Server and NetWare 6.5 SP5 has been removed from the Install program.
If you are upgrading from NetWare 6.5 FCS or later, Novell recommends that you run NWCONFIG and use Product Options to apply the SP5 updates from the update CD. This method upgrades QuickFinder™ to version 4.1 and Virtual Office to version 1.6. It also detects the version of iManager and applies either iManager 2.0.2 or iManager 2.5 updates as required.
If you want to upgrade iManager 2.0.2 to iManager 2.5, do a product install of iManager 2.5 using the NetWare 6.5 SP5 overlay CDs after you have applied the SP5 updates in NWCONFIG.
Before upgrading from NetWare 5.1 or NetWare 6.0 using the overlay CDs, you should back up any configuration files that you have customized. After the upgrade, you can restore the customized files if necessary.
In order to be upgraded to OES NetWare, NetWare 5.1 servers must have SP7 or later applied; NetWare 6.0 servers must have SP5 or later applied.
The NetWare Migration Wizard and the Novell Server Consolidation Utility have been combined under a single launch interface called the Novell Server Consolidation and Migration Toolkit. The new launch interface asks you what type of consolidation or migration project you want to perform and then launches the appropriate utility automatically: Novell Server Consolidation Utility 4.1 or NetWare Migration Wizard 8.1.
In NetWare Migration Wizard 8.1, the option to perform a full backup of the source server's trustees has been removed. Novell encourages customers to always do a full tape backup of their source server before beginning the migration. If this is done, there is no need to separately back up all the source server's trustees within the Migration Wizard.
NetWare Migration Wizard 8.1 now supports NetWare 4 as a source server, which was previously supported only in Migration Wizard 6.5.
New features in Server Consolidation Utility 4.1 include the ability to run a project as a server-based process. This means the utility does not control or monitor the actual data copying; rather, an agent running on the server processes the project. You also have the ability to migrate iPrint Print Managers and Printer Agents from a NetWare 6.5 SP3 or later environment to an OES Linux environment.
This section contains the known install/upgrade issues for this release of OES for NetWare (NetWare 6.5 SP5).
You should install one NetWare server at a time into a tree, waiting for the installation program to complete before installing an additional server into the same tree.
While installing OES, you should not initiate heavy eDirectory operations such as partitioning, mass user creation, and mass Linux User Management enabling due to slow performance. You should perform these operations after OES is installed.
When installing or upgrading to NetWare 6.5 SP5/OES on VMWare, the switch between the OS and Products CDs might not mount the Products CD. To fix this, go into the VMWare devices, disconnect the CD-ROM IDE channel, and then reconnect. The NetWare Install program should now detect and mount the Products CD.
If the ULTRA driver has been selected during the NetWare installation but refuses to load, load the IDEATA driver instead:
Return to the installation program's Drivers screen.
Select and delete the ULTRA driver.
Press Insert to select the IDEATA driver to replace it.
After installing the Support Pack, ZENworks Imaging might stop functioning. To resolve this follow the instructions in TID 10098801 on the Support Web site.
When a NetWare 6.5 server is upgraded to OES NetWare, a newer JVM* is installed that is incompatible with the zencommon.jar file in ZENworks® 6.5, so the Server Policies and Server Software Package functionalities no longer work.
To resolve this, upgrade Server Management to ZENworks 6.5 Support Pack 1 after upgrading NetWare to obtain an updated zencommon.jar file.
The OES NetWare installation overwrites ZENworks middle tier (XTier) components and upgrades XTier from version 2.0x to 3.01. However, ZENworks Desktop Management (ZDM) 6.5 and 7.0 require xTier version 2.0x for proper functionality.
ZDM 6.5 and 7.0 users must reinstall XTier after upgrading from a previous version of NetWare to OES NetWare SP1 (NetWare 6.5 SP5). Note that this impacts NetStorage functionality.
When installing OES NetWare Support Pack on a VMWare ESX Server, keep the following guidelines in mind as you configure the virtual device for your Novell Storage Services™ (NSS) volumes.
Whenever possible, you should create the virtual device in persistent mode (not undoable). In this mode, all writes are committed to the device immediately without creating a redo file.
If you create the virtual device in undoable mode, be sure to leave enough free space for the redo file to grow to the size of the partition created for the virtual server. To avoid possible problems, the virtual device should be set at twice the size of the NSS partition.
If you create the virtual device in undoable mode and don't have enough free space for the redo file, you might experience issues such as the NSS pool being deactivated or the NSS partition being deleted.
This release includes the Apache Web Server and the Jakarta-Tomcat Servlet Container. These Web service components are available on both the SUSE® LINUX Enterprise Server 9 (SLES9) and NetWare® 6.5 platforms.
If a service uses Apache, the service might hang if any module using the Apache instance does not exit immediately in response to the Apache Restart command. To avoid this problem, use the Apache Reload command instead of Restart or Start and Stop.
Beginning with OES SP1, the Tomcat certificate file for cacerts was changed to /var/opt/novell/tomcat4/conf/cacerts. This change might affect services running inside Tomcat that make a connection to an SSL-enabled service and in multiple server configurations or for signed certificates obtained from a third-party.
To resolve any of these issues, you must reimport your certificates as described in TID 10098127.
If a service uses Apache, the service might hang if any module using the Apache instance does not exit immediately in response to the Apache Restart command. To avoid this problem, use the Apache Reload command instead of Restart or Start and Stop.
By default, the internal HTTP stack of Tomcat is disabled on NetWare. If you want to use the Tomcat secure internal HTTP stack, additional configuration is required because the default NetWare SSL certificates stored in Tomcat’s keystore are not compatible with Tomcat’s secure HTTP stack.
To use the internal HTTP stack:
Uncomment out the secure and nonsecure connectors in Tomcat’s server.xml file.
(Optional) Change the ports in these connectors.
For example, if you are going to have your webapp served by Tomcat only with no Apache running at all, you probably want to change the nonsecure port to 80 and the secure port to 443. (Defaults are 8080 and 8443, respectively). Also, set the correct redirect port on the nonsecure connector to match the port set on the secure connector.
Fix the certificate problem by doing one of the following:
Create a new NCF file containing the following text and replacing appropriate items in ‑dname
keytool -keystore sys:/adminsrv/conf/.keystore -storepass apache -keypass apache -genkey -alias tomcat
-keyalg RSA -validity 9999 -dname "CN=ip_address,OU=organizationl_unit, O=organization, L=city, S=state, C=countryCode" -J-ns
At the console, execute the newly created NCF file.
To import the certificate, run the following command at the console:
keytool -import -alias tomcat -file certificatename.cer -keystore sys:/adminsrv/conf/.keystore
If, during a remote upgrade of NetWare, you accept the defaults for the LDAP server (specifically, Require TLS for Simple Binds), the Apache2 Admin Server will not get configured properly.
Any of the following resolves this issue:
Extremely high traffic volumes on the Tomcat Servlet Container can cause the mod_jk log file to grow large enough to consume the hard drive space on your server's sys: volume.
To prevent this potential problem, disable the log file:
Open the sys:\apache2\conf\httpd.conf file and locate the following lines:
JkLogFile "logs/mod_jk.log"
JkLogLevel error
Add a pound sign (#) to the beginning of each of these lines to comment them out.
Restart the Apache Web server by entering ap2webrs at the NetWare console.
(Optional) Delete the sys:\apache2\logs\mod_jk.log file, especially if it is considerably large in size to free disk space.
In the Tomcat Web application manager utility (http://domain_name/tomcat/htmlmanager/html/), some hypertext links to various Web applications might not work. This is because while the manager utility can identify the names of each installed application, it has no method for discovering the exact paths (including port numbers) to all of the applications on your server. In addition, Apache requires a trailing forward slash (/) at the end of its URL, which the manager utility does not append by default.
In most cases, this issue can be resolved by adding a forward slash (/) at the end of the URL. For example, if you clicked the /tomcat/manager link, the referenced URL might be
https://airport.newyork.digitalairlines.com/tomcat/manager
Because this URL is missing a required trailing forward slash, the browser returns an Object Not Found error message. You could then add a forward slash to the end of the URL to access the application:
https://airport.newyork.digitalairlines.com/tomcat/manager/
If the trailing slash does not fix the issue, you can access the application some other way, such as through the NetWare Welcome Web page or through Virtual Office if you have installed it.
Tomcat sometimes fails to start if there are problems with the server certificate.
If the server certificate has changed since the time of installation, you might need to export the SSL CertificateIP Trusted Root Object to sys:/public/RootCert.der using ConsoleOne® and then execute the following command at the system console:
keytool -import -v -noprompt -trustcacerts -file sys:/public/RootCert.der -keystore sys:/adminsrv/conf/.keystore -storepass changeit
Although Tomcat 5 can be installed, it has had limited testing and is unsupported in this release.