Novell CLIENT FOR LINUX 2.0 SP3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CLIENT FOR LINUX 2.0 SP3 - ADMINISTRATION:
Table of Contents

Advertisement

Quick Links

AUTHORIZED DOCUMENTATION
Administration Guide
Novell
®
Client
for Linux
TM
2.0 SP3
November 2009
www.novell.com
Novell Client 2.0 SP3 for Linux Administration Guide

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CLIENT FOR LINUX 2.0 SP3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Summary of Contents for Novell CLIENT FOR LINUX 2.0 SP3 - ADMINISTRATION

  • Page 1 AUTHORIZED DOCUMENTATION Administration Guide Novell ® Client for Linux 2.0 SP3 November 2009 www.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 2 Further, Novell, Inc., reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to notify any person or entity of such changes.
  • Page 3 Novell Trademarks For Novell trademarks, see the Novell Trademark and Service Mark list (http://www.novell.com/company/legal/ trademarks/tmlist.html). Third-Party Materials All third-party trademarks are the property of their respective owners.
  • Page 4 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 5: Table Of Contents

    Configuring OpenSLP Settings ......... 20 Configuration Files for Preconfiguring the Novell Client......21 Server Side Configuration for Sending Messages from Client to Users and Groups.
  • Page 6 Using the Novell Client for Linux Man Pages ....... . .
  • Page 7: About This Guide

    For information on login scripts, see the Novell Login Scripts Guide. Documentation Conventions In Novell documentation, a greater-than symbol (>) is used to separate actions within a step and items in a cross-reference path. ® A trademark symbol ( , etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark.
  • Page 8 When a single pathname can be written with a backslash for some platforms or a forward slash for other platforms, the pathname is presented with a backslash. Users of platforms that require a forward slash, such as Linux or UNIX, should use forward slashes as required by your software. Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 9: Understanding The Novell Client For Linux

    Linux Differs from the Novell Client for Windows 2000/XP Using the Novell Client for Linux differs in a few ways from using the Novell Client for Windows. For users and network administrators who are familiar with the Novell Client for Windows, knowing these differences can help the transition to Linux run more smoothly.
  • Page 10: Logging In

    The Novell Client for Linux can use the NMAS login method to authenticate. However, the NMAS login is not integrated in to the Novell Client for Linux login screen, so the default login sequence cannot be set in the Novell Client Login screen.
  • Page 11: Understanding The Novell Client For Linux Virtual File System

    1.2 Understanding the Novell Client for Linux Virtual File System The Novell Client for Linux differs from previous Novell Clients to enable it to work on the Linux platform. In Windows, the Novell Client loads a single binary that works on multiple operating system platforms without modifications.
  • Page 12 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 13: Configuring The Novell Client For Linux

    Groups,” on page 21 2.1 Using the Novell Client Configuration Wizard The Novell Client for Linux includes a Novell Client Configuration Wizard to simplify the process of configuring your Novell Client. 1 Launch the Novell Client Configuration Wizard by using either of the following methods: Click >...
  • Page 14: Configuring Login Settings

    If you made changes to the Protocol Settings page or the Service Location Protocol (OpenSLP) Settings page, you must reboot the machine for those changes to take effect. Any changes you make to the Novell Client settings are written to a set of configuration ( .conf files in the directory.
  • Page 15: Configuring Map Settings

    Guide. 2.1.2 Configuring Map Settings Use the Map Settings page in the Novell Client Configuration Wizard to specify the directory on the local workstation where symbolic links to network resources are created and to select the first letter to use when creating these links.
  • Page 16: Configuring Protocol Settings

    Map next 2.1.3 Configuring Protocol Settings Use the Protocol Settings page in the Novell Client Configuration Wizard to determine the level of enhanced security support, select the providers to perform name resolution, and enable the Client to obtain configuration information from your DHCP server.
  • Page 17 Dynamic Host Configuration Protocol (DHCP): If a DHCP server is set up on your network, the DHCP server can inform the Novell Client of network-specific configuration information. This information is made available when a user clicks the Tree, Context, or Server buttons on the eDirectory tab of the Novell Login dialog box.
  • Page 18: Configuring Tray Application Settings

    Use the File Browser Settings page in the Novell Client Configuration Wizard to specify which Novell Client options are available to users when they right-click Novell file system directories or files in a file manager, and which tabs are available on the Novell File, Folder, and Volume Properties pages.
  • Page 19 Novell file system directory or file in a file manager and then click Novell Properties). Novell Rights: Enables or disables the Novell Rights tab on the File and Folder Properties pages (available when users right-click a Novell file system directory or file in a file manager and then click Novell Properties).
  • Page 20: Configuring Openslp Settings

    Wizard to specify where and how the Client requests network services. In an IP-only network, the Novell Client needs a way to resolve the eDirectory tree, context and server names to an actual IP address of an eDirectory server that can provide authentication. On a simple LAN, the client can send an IP broadcast to discover this information, but on a multisite WAN, the SLP scope and Directory Agents must be listed.
  • Page 21: Configuration Files For Preconfiguring The Novell Client

    If user groups are created in a context other than the default context, then the context must be mentioned in the NDS configuration file /etc/opt/novell/eDirectory/conf/nds.conf For instance, if a user group is created in the context (organization for example) but the Configuring the Novell Client for Linux...
  • Page 22 , then to search for the groups from Novell client, the eDir administrator must add the following line in the nds.conf file: n4u.nds.bindery- context=o=xyz You must ensure that the nds daemon is restarted after the changes to the config file is completed.
  • Page 23: Managing Login

    2.0 for Linux provides a single, synchronized login to the SUSE Linux desktop or server and your Novell network. Users enter a name and password only once to access all the resources they are authorized to use. IMPORTANT: The integrated login feature is not available if you log in as the...
  • Page 24: Installing And Enabling Casa

    2 Enter your username and password, then click Advanced. 3 Specify the tree, context, and server information for the server you want to connect to. 4 Click the Startup tab, then make sure Run Novell Client Login at Session Startup is selected (it is selected by default).
  • Page 25: Enabling And Disabling Integrated Login

    5 Select Save profile after the successful login to save the Novell Login dialog settings to be used for all subsequent session logins. You must have the User Name and Password fields and the Tree and Context fields on the eDirectory tab filled out for this to be saved.
  • Page 26: Setting Up Login Scripts

    Login scripts are similar to batch files and are executed by Novell Login. You can use login scripts to map drives to Novell file system volumes and directories, display messages, set environment variables, and execute programs or menus.
  • Page 27: Using Openslp To Simplify Login

    You have access only to those features you have rights to. To have full access to all Novell iManager features, you must log in as Supervisor/Administrator of the tree. 3 Make sure you are in the Roles and Tasks view by clicking on the top button bar, then select Users >...
  • Page 28: Setting Up Slp

    For example, instead of remembering an IP address or DNS name for a server, users can select the server’s name from a list of available servers. SLP must be activated and set up on your Novell servers in order for the Novell Client to take advantage of it. For more information, see “SLP Services in the Network”...
  • Page 29: Troubleshooting Slp Configuration

    4 Complete the Novell Client Configuration Wizard. 5 Restart the workstation. 3.4.2 Troubleshooting SLP Configuration If users cannot see a list of available trees, contexts, and servers when they use the Novell Client for Linux Login screen, use , located in , to troubleshoot your SLP configuration.
  • Page 30 3 Click Stop Firewall Now, then click Next. 4 Click Accept to close the Firewall Configuration Wizard. The next time you click the Novell Services button in your file browser, you should be able to scan for or access Novell services.
  • Page 31 #FW_CUSTOMRULES="/etc/sysconfig/scripts/SuSEfirewall2-custom" FW_CUSTOMRULES="" FW_CUSTOMRULES="/etc/sysconfig/scripts/SuSEfirewall2-custom" #FW_CUSTOMRULES="" 2 Modify the file. /etc/sysconfig/scripts/SuSEfirewall2-custom add the following: fw_custom_before_denyall() iptables -I INPUT 1 -j ACCEPT -p udp --sport 427 That will make SLP lookups work properly. Adding SLP Daemon Rules for External or DMZ Firewall Zones 1 Launch the YaST Control Center.
  • Page 32 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 33: Managing File Security

    Administrator account can delete or rename a file that other users can only open and edit. The Novell file system keeps track of the rights that users have to files and directories on the network. When users try to access any file on the network, Novell File Service (NFS) either grants access or prohibits certain things that users can do with the file.
  • Page 34 Rights Concepts (http://www.novell.com/documentation/edir88/edir88/data/ fbachifb.html) in the Novell eDirectory 8.8 Administration Guide for more information). Rights can also be limited by Inherited Rights Filters and changed or revoked by lower trustee assignments. The net result of all these actions—the rights a user can employ—are called effective rights.
  • Page 35: Changing Trustee Rights

    Rights and filters. 4.3 Adding a Trustee When you add a trustee to a Novell file system directory or file, you grant a user (the trustee) rights to that directory or file.You must have the Access Control right to add a trustee.
  • Page 36: Removing A Trustee

    6 Click OK. 4.4 Removing a Trustee When you remove a trustee of a Novell file system directory or file, you delete a user’s rights to that directory or file. You must have the Access Control right to remove a trustee.
  • Page 37 Michael has Read, Write, and File Scan rights to both FILEA and FILEB. To combine multiple trustees: 1 In a file manager, select all the Novell files or directories that you want to combine rights for. 2 Right-click the files or directories, then select one of the following: GNOME: Click Novell Properties.
  • Page 38 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 39: Security Considerations

    Section 5.4, “New and Modified Files,” on page 41 Section 5.5, “Other Security Considerations,” on page 44 5.1 Security Features ® The following table contains a summary of the Novell Client for Linux security features: Novell Client for Linux Security Features...
  • Page 40: Known Security Threats

    FIPS-compliant. 5.2 Known Security Threats The following section provides a list of known security threats for the Novell Client for Linux, an indication of how difficult it would be to exploit the threat, and what the consequences would be for a customer.
  • Page 41: Identification And Authentication

    5.4 New and Modified Files The following sections describe the files that are added or modified during the installation of the Novell Client for Linux. Section 5.4.1, “Configuration Files,” on page 42 Section 5.4.2, “PAM Login Files,” on page 42 Section 5.4.3, “User Profile Startup Files,”...
  • Page 42: Configuration Files

    YaST through the Novell Client Configuration Wizard for the login page (click the Novell Tray icon, select System Settings, and start the Login wizard). 5.4.2 PAM Login Files New and Modified PAM Login Files Table 5-4...
  • Page 43: User Profile Startup Files

    /opt/novell/ncl/bin/ saving settings. This file adds a new tab (called gnwlogin Startup) to the Novell Login dialog box, which allows users to save their current login settings for use during the next system startup to automatically log in the user.
  • Page 44: Other Security Considerations

    For example, if a malicious root entity gets access, it might be able to steal user credentials and authenticate to the network root with those credentials. Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 45: Troubleshooting Tips

    LUM is configured. After the user logs in to the desktop on which Linux User Management (LUM) is configured, Novell Client tray might sometimes display the following error message: The novfs kernel loadable module is not installed correctly This occurs because namcd fails to start in the machine.
  • Page 46 3. Restart novfsd as root by running the following command: rcnovfsd restart 4. Manually launch Novell Client tray application by running the command /opt/novell/ncl/ either on the command line of a terminal window or in Run Application utility bin/ncl_tray that can be launched by pressing Alt-F2.
  • Page 47: A The Novell Client For Linux Command Line Utilities

    Novell file systems, log a user in to or out of a Novell file server or eDirectory tree, map a local file system to a remote file system on a Novell file server, and display or modify a user’s trustee assignments or inherited rights filter for volumes, directories, or files.
  • Page 48: Gui Utilities

    (instead of the traditional command) to view NCL-related man pages. To do this, enter the following in a terminal the first time you want to view a Novell Client for Linux man page: /opt/novell/ncl/bin/ncl_man This modifies the MANPATH to allow the Novell Client man pages to be displayed.You can then...
  • Page 49 You can also enter in a terminal window to access a help page for the utility_name --help utility. For more information, see Appendix B, “Novell Client for Linux Man Pages,” on page The Novell Client for Linux Command Line Utilities...
  • Page 50 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 51: B Novell Client For Linux Man Pages

    Novell Client for Linux Man Pages “gnwlogin(1)” on page 52 “login.conf(4)” on page 55 “mapdrives.conf(4)” on page 57 “ncl_install(8)” on page 59 “ncl_man(1)” on page 61 “ncl_tray(1)” on page 62 “nwconnections(1)” on page 63 “nwcopy(1)” on page 64 “nwflag(1)” on page 66 “nwlogin(1)”...
  • Page 52: Gnwlogin

    -] [-v][-h] Description The gnwlogin utility allows a user to log in to a Novell file server or eDirectory tree. Running the gnwlogin command launches the Novell Login dialog box. You can add variables and strings to run additional scripts and modify variables.
  • Page 53 The variables are replaced in the order specified, by selecting -2, -3, -4, or -5. -2 <value>, --var2 <value> Allows an additional parameter to be entered that the login utility passes to the login script. Novell Client for Linux Man Pages...
  • Page 54 Displays version information and exits. --h, --help Display usage information and exits. Authors Copyright 2007-2009, Novell, Inc. All rights reserved. http://www.novell.com See Also nwlogin(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 55: Login.conf

    This file can be modified only by the user, normally with YaST through the Novell Client root Configuration Wizard for the login page (click the Novell Tray icon, select System Settings, and start the Login Wizard). Usage Each entry occupies a single line in the file. Lines that are blank, or that start with a pound sign (#), are ignored.
  • Page 56 Clear_Username=true Allow_Integrated_Login=false Default_Tree=mycompany Default_Context=marketing Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 57: Mapdrives.conf

    Name - Novell Client for Linux user configuration file. mapdrives.conf Files $HOME/.novell/ncl/MapDrives.conf Description Allows you to specify drive mappings to run at startup. Integrated Login is not required, but credentials must be saved or the login dialog box appears to get the password at desktop startup.
  • Page 58 Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 59: Ncl_Install

    [ install | upgrade | uninstall | verify | information | files ] [ force ] Description Allows you to install, upgrade, and uninstall the Novell Client for Linux packages. You can also run it to verify the installation of the files. You must be logged in as to run this utility.
  • Page 60 Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 61: Ncl_Man

    Syntax ncl_man <Novell Client man page name> Description The ncl_man utility modifies the MANPATH to allow the Novell Client man pages to be displayed. If you enter , the following error is displayed: man <Novell Client man page name>...
  • Page 62: Ncl_Tray

    [--waitfortray <integer>] [--author] [--] [-v] [-h] Description Allows you to manually load the Novell Client for Linux tray application. This application provides GUI access to Novell Client functionality such as login, logout, mapping drives, and many other functions. It requires the X Windows System to be running, because it is a GUI application.
  • Page 63: Nwconnections

    Displays the version for the package that supplies the nwconnections utility. -h, -help Displays the help strings. Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com See Also nwmap(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 64: Nwcopy

    [-f] [-c] [-s] -t <target_path> -p <source_path> [--] [-v] [-h] Description The nwcopy utility allows you to copy files and directories to and from Novell file systems. Using nwcopy preserves Novell file system attributes. NOTE: The source and target must be Novell file system (Netware traditional file system or Novell storage services).
  • Page 65 -f -p my_vol -t your_vol Copies all files or directories from and rewrites the existing targets. my_vol your_vol Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 66: Nwflag

    Name - Displays or modifies the attributes of files and directories on Novell file systems. nwflag Syntax nwflag {-a|-n} {-w|-e <eDir object>|<+|-> <attr modifier>} [-s] [-d|-f] [--] [-v] [-h] <URI1> {URI2} {URI3} ... Description The nwflag utility allows you to display and modify the attributes of files or directories.
  • Page 67 For additional information on file system attributes, see the File Systems Management Guide for OES at http://www.novell.com/documentation/oes/stor_filesys/data/hn0r5fzo.html. In this guide, the “Understanding File System Access Control for NSS and NetWare Traditional File Systems” section provides information on flags. See http://www.novell.com/documentation/oes/ stor_filesys/data/bs3fih1.html. o=Read-only...
  • Page 68 -n -w -s -f //MYSERVER/USER | grep -i “adam.cont.org” Lists all files owned by user ADAM on volume USER. Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 69: Nwlogin

    [-r] [-L <string>] [-P <string>] [-2 <string>] [-3 <string>] [-4 <string>] [-5 <string>] [--clearconn] [--] [-v][-h] Description The nwlogin utility allows a user to log in to a Novell file server or eDirectory tree from a terminal. When you execute the command, you can add variables and strings to run additional nwlogin scripts and modify variables.
  • Page 70 Displays usage information and exits. Examples nwlogin -s MYSERVER -u MYUSER -c MYCONTEXT -t MYTREE -p MYPASSWORD -2 MYVARIABLE L P r nwlogin -u MYUSER -p MYPASSWORD -t MYTREE -c MYCONTEXT -s MYSERVER Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 71 Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com See Also nwlogout(1), nwconnections(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 72: Nwlogout

    Syntax nwlogout {-s <string>|-t <string>|-a} [-f] [--] [-v] [-h] Description The nwlogout utility allows a user to log out of a specific Novell file server or eDirectory tree or to log out of all trees and servers. Options Required: -s <string>, --server <string>...
  • Page 73 Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com See Also nwlogin(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 74: Nwmap

    Name - Creates a mapping (mount) from a local file system to a remote file system on a Novell file nwmap server. Syntax map -d drive <-s server> -v volume <-f filespec> map <<options> | <parameters> drive:=<path> | local_path:=<remote_path>>...
  • Page 75 Maps the next available drive when used without specifying a drive number or letter. Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 76: Nwpurge

    {-l|-a|-r|-f <string> ... } [--] [-v] [-h] <FileSystem objects to perform operations with> ... Description The nwpurge utility enables you to purge deleted files and directories from Novell file system. Options -l, --list Displays the objects to be purged.
  • Page 77 See Also nwsalvage(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 78: Nwrights

    >rights_list |-w|-e} [-o <string>] [-s] [--] [-v] [-h] <FileSystem objects to perform operation with> ... Description The nwrights utility allows you to display and give rights to files and directories on a Novell server. Rights can be given directly or through inherited rights filters. Options View the trustees, inheritance filter, or effective rights.
  • Page 79 -t -m +r -o "abc.xyz" dir1 Assigns read access to the trustee abc.xyz. Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 80: Nwsalvage

    ... Description The nwsalvage utility enables you to salvage deleted files and directories from Novell file system. In a hierarchical directory structure, you must use this utility to salvage files or directories at each level of the directory structure before proceeding to the next level.
  • Page 81 Salvages all file system objects at the current level. nwsalvage -f file1 /home/localuser1/VKNSSVOl1/Salvage1/Salvage12/ Salvages only the specified objects. Authors Copyright 2005-2009, Novell, Inc. All rights reserved. http://www.novell.com See Also nwpurge(1) To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 82: Nwsend

    Name - Sends messages to users or groups who are currently connected to a Novell server or sends nwsend a message to the server console. Syntax nwsend <flags> -s <target_server> -o <fully_distinguished_user_name> -m <message_text> Description The nwsend utility allows you to send messages to users or groups who are currently connected to a Novell server, or allows you to send a message to the server console.
  • Page 83: Startuplogin.conf

    - Novell Client for Linux user configuration file. StartupLogin.conf Files $HOME/.novell/ncl/StartupLogin.conf Description All the current fields in the Novell Login dialog box (except the password) are stored in this configuration file. This file uses the same format as the file. login.conf Usage Each entry occupies a single line in the file.
  • Page 84 These variables are replaced in order by the parameters the user entered when logging in. AllowLoginGUI=[true or false] The default is true. If eDirectory authentication fails, display Novell Login dialog during session startup (after initial login). Examples...
  • Page 85 Variable3 = Variable4 = Variable5 = Authors Copyright 2007-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 86: Startupmaps.conf

    Append to UserName for a fully distinguished name. Mapped=<filesystem_path> For example: Mapped = \\mycompany\sys: [/home/<username>/Desktop/next_drive] Examples A sample file is given below: StartupMaps.conf [/home/mycompany/Desktop/xyzzy] UserName = admin.novell Tree = MYCOMPANY_TREE Context = Mapped = \\mycompany\sys: Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 87 [/home/mycompany/Desktop/pub] UserName = admin.novell Tree = MYCOMPANY_TREE Context = Mapped = \\mycompany\SYS:PUBLIC\ Authors Copyright 2007-2009, Novell, Inc. All rights reserved. http://www.novell.com To report problems with this software or its documentation, visit http://bugzilla.novell.com Novell Client for Linux Man Pages...
  • Page 88 Novell Client 2.0 SP3 for Linux Administration Guide...
  • Page 89: C Documentation Updates

    Documentation Updates This section contains information on documentation content changes made in this guide since the ® initial release of the Novell Client for Linux. The information will help you keep current on updates to the documentation. The documentation was updated on the following dates: Section C.1, “September, 2009,”...
  • Page 90 Novell Client 2.0 SP3 for Linux Administration Guide...

Table of Contents