<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>NOVELL FORUMS - eDir: Linux</title>
		<link>http://forums.novell.com/</link>
		<description />
		<language>en</language>
		<lastBuildDate>Sun, 22 Nov 2009 07:17:24 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://forums.novell.com/images/ca_serenity/misc/rss.jpg</url>
			<title>NOVELL FORUMS - eDir: Linux</title>
			<link>http://forums.novell.com/</link>
		</image>
		<item>
			<title>Apply network restrictions to LDAP Proxy user</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393509-apply-network-restrictions-ldap-proxy-user.html</link>
			<pubDate>Sat, 21 Nov 2009 04:08:20 GMT</pubDate>
			<description>(re-post from OES Client forum) 
 
Implemented LDAP contextless login using an LDAP Proxy user, and that is working fine. 
 
Since the LDAP Proxy...</description>
			<content:encoded><![CDATA[<div>(re-post from <acronym title="Open Enterprise Server">OES</acronym> Client forum)<br />
<br />
Implemented LDAP contextless login using an LDAP Proxy user, and that is working fine.<br />
<br />
Since the LDAP Proxy user has null password, I wish to lock it down in some way since anyone who knows or guesses the username can login to the directory (not a huge concern but still, want to be thorough).<br />
<br />
As far as I can tell from the docs, the only thing I can really do is impose network address restrictions on it (&quot;You can limit the locations that the user can log in from by setting address restrictions for the Proxy User object.&quot;)<br />
<br />
However, exactly what addr restrictions can / should I impose (such as are just the server IPs of the LDAP servers enough?) and especially, will imposing the address restriction have impact on any other services? Using OES2SP1-Linux and also using NSS clustering if it matters.<br />
<br />
Thanks<br />
GM</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>gmarsh</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393509-apply-network-restrictions-ldap-proxy-user.html</guid>
		</item>
		<item>
			<title>pre/post_ndsd scripts moved?</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393322-pre-post_ndsd-scripts-moved.html</link>
			<pubDate>Thu, 19 Nov 2009 19:17:01 GMT</pubDate>
			<description>I was looking in /etc/init.d for the pre/post_ndsd_stop/start scripts and could not find them.  I then searched and found they were moved to...</description>
			<content:encoded><![CDATA[<div>I was looking in /etc/init.d for the pre/post_ndsd_stop/start scripts and could not find them.  I then searched and found they were moved to /opt/novell/eDirectory/sbin (and appear to be working just fine).  I then looked at another server and found them still in /etc/init.d.  The server with the moved scripts was recently upgraded to 8.8.5 FTF1.  Was this script move part of the upgrade?  I looked at the docs and don't see any mention of moving the scripts but I may have missed it somewhere.  Thanks.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>cperilli</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393322-pre-post_ndsd-scripts-moved.html</guid>
		</item>
		<item>
			<title>8.8.5 FTF1, how critical?</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393130-8-8-5-ftf1-how-critical.html</link>
			<pubDate>Wed, 18 Nov 2009 13:30:13 GMT</pubDate>
			<description>We have a very strict procedure we need to follow on any software updates.  Everything needs to go through a documented test cycle before going into...</description>
			<content:encoded><![CDATA[<div>We have a very strict procedure we need to follow on any software updates.  Everything needs to go through a documented test cycle before going into production.  Testing has been completed for 8.8.5 but the test cycle was started before FTF1 was out.  We are scheduled to do the production upgrade to 8.8.5 this weekend.  We have already started testing on FTF1 but it will not complete the cycle for weeks.  Is 8.8.5 &quot;safe&quot; to install without FTF1 or are there some critical problems in unpatched 8.8.5 that would make that a bad idea.  We have had no issues with our local testing.  Our eDirectory environment is all based on SLES10.2 boxes used for IDM and LDAP authentication purposes.<br />
<br />
Also, it sure would be nice if Novell provided install scripts with FTFs.  FTF1 is 17 rpms.  The documentation says this is a &quot;manual&quot; installation.  On 20+ servers?...NOT!  Of course we write scripts to take care of it but it would be nice if the scripts were provided.  Just a friendly suggestion if Novell is listening.<br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>cperilli</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393130-8-8-5-ftf1-how-critical.html</guid>
		</item>
		<item>
			<title>Where to download eDirectory 8.8 SP3 for SLES10 64bit?</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393090-where-download-edirectory-8-8-sp3-sles10-64bit.html</link>
			<pubDate>Wed, 18 Nov 2009 04:11:48 GMT</pubDate>
			<description><![CDATA[HI, 
 
I need someone here to provide me the link to download "eDir_88_SP3_Linux-x86_64". 
 
Thanks.]]></description>
			<content:encoded><![CDATA[<div>HI,<br />
<br />
I need someone here to provide me the link to download &quot;eDir_88_SP3_Linux-x86_64&quot;.<br />
<br />
Thanks.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>lihtian</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/393090-where-download-edirectory-8-8-sp3-sles10-64bit.html</guid>
		</item>
		<item>
			<title>MS AD to Novell eDirectory migration ?</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392974-ms-ad-novell-edirectory-migration.html</link>
			<pubDate>Tue, 17 Nov 2009 12:09:26 GMT</pubDate>
			<description>is there any migration tool available that migrates MS AD 2003 objects(ou, users, groups, computers, printers) to Novell eDirectory ? 
 
if yes, then...</description>
			<content:encoded><![CDATA[<div>is there any migration tool available that migrates MS AD 2003 objects(ou, users, groups, computers, printers) to Novell eDirectory ?<br />
<br />
if yes, then when migrating from MS AD 2003 to Novell eDirectory... does the passwords of MS AD 2003 users, also  migrates to Novell eDirectory ?<br />
<br />
e.g in MS AD, a user name 'abc' has passowrd 'abc123+', does the password remains same in Novell eDirectory ?<br />
<br />
regards<br />
needee</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>needee</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392974-ms-ad-novell-edirectory-migration.html</guid>
		</item>
		<item>
			<title>Import certificate after server rebuild</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392768-import-certificate-after-server-rebuild.html</link>
			<pubDate>Mon, 16 Nov 2009 21:39:17 GMT</pubDate>
			<description>Question about certificates (third party, specifically).  If I have a third party cert loaded into a PKI Key Material object, and I then rebuild that...</description>
			<content:encoded><![CDATA[<div>Question about certificates (third party, specifically).  If I have a third party cert loaded into a PKI Key Material object, and I then rebuild that server (say to move from Netware 6.5 to SLES), is it possible to reimport that cert if I've exported it with the private key?  Or do I have to go get another one from Verisign or wherever?  I know that you can replace the cert in iManager, but I'm wondering if the key pairs will still be valid since I would have had to generate a new key pair to get the new object out there.  I haven't done this before and I really don't have spare Verisign certs to test with. =)</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>infinity9999</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392768-import-certificate-after-server-rebuild.html</guid>
		</item>
		<item>
			<title>ERROR -1497  DDSInit failed.</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392751-error-1497-ddsinit-failed.html</link>
			<pubDate>Mon, 16 Nov 2009 19:28:20 GMT</pubDate>
			<description><![CDATA[I am attempting to run 
 
ndsconfig new def -s ServerName -t mytree -n o=org -a "admin.pipsc" 
 
and I get the above error 
 
ERROR -1497  DDSInit...]]></description>
			<content:encoded><![CDATA[<div>I am attempting to run<br />
<br />
ndsconfig new def -s ServerName -t mytree -n o=org -a &quot;admin.pipsc&quot;<br />
<br />
and I get the above error<br />
<br />
ERROR -1497  DDSInit failed.<br />
<br />
eDirectory 8.8 on a suse 10 Enterprise server<br />
<br />
I have gone through the prerequisistes and I think I have everything.<br />
<br />
I'm not using SLP so I created a hosts.nds<br />
I didn't install nici,  I don't currently use it on any of our NetWare<br />
servers.<br />
<br />
Thanks for the insight<br />
</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>candaced</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392751-error-1497-ddsinit-failed.html</guid>
		</item>
		<item>
			<title>LDAP logins - best practices</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392723-ldap-logins-best-practices.html</link>
			<pubDate>Mon, 16 Nov 2009 16:20:02 GMT</pubDate>
			<description><![CDATA[Hi all, 
Got a question about how best to provision LDAP services in a network.  We've got eDirectory logins configured via ldap for many Macintosh...]]></description>
			<content:encoded><![CDATA[<div>Hi all,<br />
Got a question about how best to provision LDAP services in a network.  We've got eDirectory logins configured via ldap for many Macintosh client machines throughout our county.  Our county's server structure is 4 replicas physically spread around, with each school having a dedicated sles/oes2sp1 server that handles dhcp and iprint, they are not replicas.. I have configured the mac ldap clients at each school reference their own school's Linux OES2sp1 server for ldap logins - thinking this would help load balance.<br />
What we've found sofar is that if an entire lab logs in at one time, the logins slow to a crawl - taking 2 minutes or more to fully go from login screen to a usable desktop.   One fix that we've found right now is to reconfigure the clients to point directly at one of the replicas.  <br />
We're doing this for labs currently, but now my worry is at what point that will overload the replica server.  Is there a best practice for this?  Is there a way to speed up the logins on the non-replica school servers?  Should I just point everything at that one server and feel confident that it can handle the load? <br />
Thanks<br />
P</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>petefuller</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392723-ldap-logins-best-practices.html</guid>
		</item>
		<item>
			<title>Auxiliary Class</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392693-auxiliary-class.html</link>
			<pubDate>Mon, 16 Nov 2009 11:52:37 GMT</pubDate>
			<description>Guys, if I have created an Auxiliary class with some optional attributes, can I add on later with some mandatory attributes? As I try to do such...</description>
			<content:encoded><![CDATA[<div>Guys, if I have created an Auxiliary class with some optional attributes, can I add on later with some mandatory attributes? As I try to do such action in iManager but can't find the way. Thx</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>kkyen</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392693-auxiliary-class.html</guid>
		</item>
		<item>
			<title>edir 885FTF1 Java crash</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392681-edir-885ftf1-java-crash.html</link>
			<pubDate>Mon, 16 Nov 2009 09:17:27 GMT</pubDate>
			<description>this morning editr on my IDM server was down and ndsd.log has the following: 
 
Nov 13 11:12:28  Repair utility for Novell eDirectory 8.8 - 8.8 SP5...</description>
			<content:encoded><![CDATA[<div><br />
this morning editr on my IDM server was down and ndsd.log has the following:<br />
<br />
Nov 13 11:12:28  Repair utility for Novell eDirectory 8.8 - 8.8 SP5 v20501.00 Successfully loaded<br />
Nov 13 11:12:28  Repair utility for Novell eDirectory 8.8 - 8.8 SP5 v20501.00 Successfully unloaded<br />
#<br />
# An unexpected error has been detected by Java Runtime Environment:<br />
#<br />
#  SIGSEGV (0xb) at pc=0xb09ee4cc, pid=28172, tid=2499664800<br />
#<br />
# Java VM: Java HotSpot(TM) Server VM (10.0-b22 mixed mode linux-x86)<br />
# Problematic frame:<br />
# CNov 16 09:30:34  Path of Novell eDirectory configuration file /etc/opt/novell/eDirectory/conf/nds.conf<br />
Nov 16 09:30:36  Host process for Novell eDirectory 8.8 SP5 v20501.00 successfully started<br />
Nov 16 09:30:36  DHLog: file size 1048576<br />
[ -- DHost Logging STARTED Mon Nov 16 09:30:36 2009 -- ]<br />
Nov 16 09:30:36  MASV Init called<br />
<br />
any idea where to look for the cause? Individual driver traces don't show any error messages ,they all just end on saturday evening withing a 5 min timeframe...<br />
<br />
Cheers, Lothar<br />
</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>lhaeger</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392681-edir-885ftf1-java-crash.html</guid>
		</item>
		<item>
			<title>Certificate chain with AD</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392660-certificate-chain-ad.html</link>
			<pubDate>Sun, 15 Nov 2009 22:12:39 GMT</pubDate>
			<description>wanting to know if it is possible to chain an eDirectory certificate server as a subordinate to an active directiry root server. I have read in the...</description>
			<content:encoded><![CDATA[<div>wanting to know if it is possible to chain an eDirectory certificate server as a subordinate to an active directiry root server. I have read in the documentation that it is possible to chain with 3rd party such as verisign. I also want to know if this is possible without the need to delete the existing CA from my tree. I basically want to be able to issue certificates as subsiduary1.company.com from an eDirectory server, but have company.com remain as the active directory root certificate server.</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>pcoombs</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392660-certificate-chain-ad.html</guid>
		</item>
		<item>
			<title>eDirectory Design</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392638-edirectory-design.html</link>
			<pubDate>Sun, 15 Nov 2009 12:11:45 GMT</pubDate>
			<description>Hi, 
 
We are creating eDirectory design and after discussion with novell expert, we have finalized two strategy based on experince we have. I am...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
We are creating eDirectory design and after discussion with novell expert, we have finalized two strategy based on experince we have. I am giving details of our network.......<br />
<br />
Let say, our organization XYZ is speaded around the globe with having around 30,000 associates. In the organization, we have 3 countries with organization structure as 4 departments and almost 6-7 sub departments in every department and we have almost 10,000 associates accessing the eDir from geographically different locations.<br />
<br />
Now we are working two kind of designs as described below:<br />
<br />
Design Strategy A:<br />
---------------------------<br />
O=XYZ-TREE<br />
|--C=X1<br />
|   |--OU=Dep1<br />
|   |    |--OU=SubDep1<br />
|   |         |--OU=Users<br />
|   |         |--OU=Resources<br />
|<br />
|<br />
|--C=X2<br />
|   |----<br />
-----------------------------------<br />
NOTE: We have hierarchy as Organization-Country-Department-Sub Department. And under each sub-department we have two containers named, Users and Resources. Users contains the all Users belongs to the particular sub-department and resources contains the shared resources for that sub-department. We found that there are multiple resources which are shared within multiple departments so we created Resources container and put all resources under that by sub-department. If any resource is being shared by any other sub-department then we create alias of the resource in that sub-department’s resources.<br />
<br />
Benefits of this kind of structure is, we could easily partition and create the server based on geographical requirements.<br />
<br />
Design Strategy B:<br />
---------------------------<br />
O=XYZ-TREE<br />
|--OU=Users<br />
|--OU=Resources<br />
|<br />
|--C=X1<br />
|   |--OU=Dep1<br />
|   |    |--OU=SubDep1<br />
|<br />
|<br />
|--C=X2<br />
|   |----<br />
<br />
Note: Although the above strategy is same as explained in A with the difference is User and resources containers are placed just below to the Organization and Users and Resources are linked with the department, sub-department using attributes.<br />
<br />
What you would suggest to opt for better eDirectory extendable structure?<br />
<br />
Thanks in advance for your recommendation.<br />
HeavenAlive</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>HeavenAlive</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392638-edirectory-design.html</guid>
		</item>
		<item>
			<title>Re-imported cert not the same</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392423-re-imported-cert-not-same.html</link>
			<pubDate>Thu, 12 Nov 2009 15:43:34 GMT</pubDate>
			<description>We have a problem where eDirectory (8.8.1) keeps corrupting its database.  The most annoying part about having to reinstall is that the server in...</description>
			<content:encoded><![CDATA[<div>We have a problem where eDirectory (8.8.1) keeps corrupting its database.  The most annoying part about having to reinstall is that the server in question is the CA.  To avoid having to update all the LDAPS clients with a new cert,  I exported the CA certificate with its private key into a .pfx file using iManager (2.6).  <br />
<br />
(Yes, these are old versions, the upgrade project is moving slowly...)<br />
<br />
I tried deleting the CA object and recreating it with the wizard as an import, but it threw a null pointer exception and SSL operations logged errors to dstrace about not being able to access the server's KMO.  <br />
<br />
So I deleted the CA again and recreated it using default settings, but then used the Replace option on the certificates tab to replace the CA certificate with the exported .pfx file.  <br />
<br />
That seemed to work, but the cert is not the same as it was before.  It has the same serial number but a different RSA modulus. <br />
<br />
So what am I doing wrong?  How do I get the same cert I had before?  If I didn't do the export properly, what are the missing steps so I can at least avoid having to do this yet again?</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>markjreed</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392423-re-imported-cert-not-same.html</guid>
		</item>
		<item>
			<title>User Object Class</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392361-user-object-class.html</link>
			<pubDate>Thu, 12 Nov 2009 06:50:53 GMT</pubDate>
			<description>I am working on eDirectory from past 6months or so and found one fact to clarify. It is related to User ObjectClass. 
 
I was just browsing eDir and...</description>
			<content:encoded><![CDATA[<div>I am working on eDirectory from past 6months or so and found one fact to clarify. It is related to User ObjectClass.<br />
<br />
I was just browsing eDir and found that if i search eDir to find the User having ObjectClass=User, it result me all User object but if i look at the ObjectClass values of the serached Users, i do not see any value having &quot;User&quot;. I am sure that it coz we search User thru LDAP API and there must be some twiking on that (correct me if I am wrong).<br />
<br />
It is quite similar to encapsulation concept. Now my question is, how could we create Object class with same functionality?<br />
<br />
Somthing like, I want to create object class named &quot;A&quot; and in search, i would be able to search the &quot;A&quot; objects with &quot;B&quot;.<br />
<br />
Thanks in advance!!</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>rajeshemailto</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392361-user-object-class.html</guid>
		</item>
		<item>
			<title>replicas showing as replicas but not replicating</title>
			<link>http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392321-replicas-showing-replicas-but-not-replicating.html</link>
			<pubDate>Wed, 11 Nov 2009 22:29:10 GMT</pubDate>
			<description>We have a sles10 sp2 oes2 sp1 server that is in eDirectory as a replica server.  However in our ds ring it is not showing up. It shows up as synched...</description>
			<content:encoded><![CDATA[<div>We have a sles10 sp2 oes2 sp1 server that is in eDirectory as a replica server.  However in our ds ring it is not showing up. It shows up as synched for time but it will not show up in our replica ring.  Any ideas?</div>

]]></content:encoded>
			<category domain="http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/">eDir: Linux</category>
			<dc:creator>lilott8</dc:creator>
			<guid isPermaLink="true">http://forums.novell.com/novell-product-support-forums/edirectory/edir-linux/392321-replicas-showing-replicas-but-not-replicating.html</guid>
		</item>
	</channel>
</rss>
