6.6 Setting Up the Server

In Novell SecureLogin 6.0 and later, the server setup to support terminal server integration is automated. You are not required to do any manual setup.

In the process, the following files are copied to the Windows system directory, such as c:\winnt\system32:

If Novell SecureLogin is installed on the server in LDAP mode, then srv\slaa_sso.dll is also copied to the Windows system directory.

6.6.1 Setting the GINA

If you are using Novell SecureLogin 6.0 or later, the installation automatically installs the necessary binaries and configures the server. In such case, you can skip the following steps.

Servers with the Novell Client

  1. Set up a Novell login extension. Copy srv\nw\slinas.dll to the Windows system directory, (for example, c:\winnt\system32

  2. Register the login extension.

    In the srv\nw directory, double-click Register NTLoginExt.reg.

  3. Follow the on-screen instructions to finish the registration.

Servers without the Novell Client

  1. Replace the server GINA. Copy srv\ms\sl_tsgina.dll to the Windows system directory (for example, c:\winnt\system32

  2. Register the login extension. In the srv\nw directory, double-click winlogon_server.orgTLoginExt.reg.

  3. Follow the on-screen instructions to finish the registration.

  4. Reboot the server.

6.6.2 Configuring OnDemand

If you have set up a Microsoft Terminal Server with Novell ZENworks® OnDemand Services™ installed, you don’t need to install any new components for Novell SecureLogin. OnDemand relies on the DeFrame™ ICA or RDP plug-ins as the client. No workstation components are necessary. When a user authenticates to the Citrix session, Novell SecureLogin launches.

If you use the SecretStore option with OnDemand Dynamic User Creation, make the following changes to the EnableUserProfileDirectory value in the HKEY_LOCAL_MACHINE\SOFTWARE\NOVELL\NICI registry key:

Value

Type

Description

EnableUserProfileDirectory

DWORD

NICI user files are created in the Application Data\Novell\NICI directory in the user’s profile directory

The NICI installation program does not create EnableUserProfileDirectory. Therefore, this value is disabled.

NOTE:If the user directory is enabled, NICI does not set the Access Control Lists (ACL) on this directory. NICI relies on the existing security properties (ACLs, inheritance, and ownership) of the user’s profile directory.

To configure a DeFrame application object to launch Internet Explorer, when Internet Explorer is using the ICA protocol:

  1. In ConsoleOne®, right-click the Application object.

  2. Select DeFrame, then click Application Setup.

  3. Add SLLauncher.exe.

    Enclose path\applicationname in quotation marks (for example, "c:\Program Files\Novell\SecureLogin\SLLauncher.exe" "c:\Program Files\Internet Explorer\iexplore.exe").

  4. Install the Novell SecureLogin client at the Citrix/DeFrame server.