Table of Contents

Advertisement

Quick Links

Novell iFolder 3.x Administration Guide
Novell
iFolder
®
w w w . n o v e l l . c o m
3 . x
A D M I N I S T R A T I O N G U I D E
A u g u s t 1 5 , 2 0 0 6

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the IFOLDER 3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for Novell IFOLDER 3 - ADMINISTRATION

  • Page 1 Novell iFolder 3.x Administration Guide Novell iFolder ® w w w . n o v e l l . c o m 3 . x A D M I N I S T R A T I O N G U I D E...
  • Page 2 Further, Novell, Inc., reserves the right to make changes to any and all parts of Novell software, at any time, without any obligation to notify any person or entity of such changes.
  • Page 3 Novell Trademarks For a list of Novell trademarks, see the Novell Trademark and Service Mark list (http://www.novell.com/company/ legal/trademarks/tmlist.html). Third-Party Materials All third-party trademarks are the property of their respective owners.
  • Page 5: Table Of Contents

    What’s New in Novell iFolder 3.2 (OES SP2 Linux)....... . .
  • Page 6 Accessing iManager and the Novell iFolder 3 Plug-In ....... 59...
  • Page 7 Accessing the Novell iFolder 3 Plug-In for iManager ....... .
  • Page 8 Installing Novell Cluster Services for Linux ........
  • Page 9 Product History of iFolder 3.x ......... 145 August 19, 2005 (Novell iFolder 3.1 for OES SP1 Linux) ......145 E.4.1...
  • Page 10 Novell iFolder 3.x Administration Guide...
  • Page 11: About This Guide

    Please use the User Comment feature at the bottom of each page of the online documentation, or go to www.novell.com/documentation/feedback.html and enter your comments there. Documentation Updates For the most recent version of the Novell iFolder 3.x Administration Guide, visit the Novell iFolder 3.x documentation Web site (http://www.novell.com/documentation/ifolder3/index.html).
  • Page 12 • Novell Technical Support (http://www.novell.com/support) Documentation Conventions In Novell documentation, a greater-than symbol (>) is used to separate actions within a step and items in a cross-reference path. ® A trademark symbol ( , etc.) denotes a Novell trademark. An asterisk (*) denotes a third-party trademark.
  • Page 13: Overview Of Novell Ifolder 3.X

    “No Training Requirements” on page 15 1.1.1 Seamless Data Access Novell iFolder greatly simplifies the IT department’s ability to keep users productive. It empowers users by enabling their data to follow them wherever they go. The days of users e-mailing themselves project files so they can work on them from home are gone, along with the frustration associated with sorting through different versions of the same file on different machines.
  • Page 14: Data Safeguards And Data Recovery

    1.1.2 Data Safeguards and Data Recovery With Novell iFolder, data stored on the server can be easily safeguarded from system crashes and disasters that can result in data loss. When a user saves a file locally, the iFolder client can automatically update the data on the iFolder server, where it immediately becomes available for an organization’s regular network backup operations.
  • Page 15: Productive Mobile Users

    IT personnel no longer need to condition or train users to perform special tasks to ensure the consistency of data stored locally and on the network. With Novell iFolder, users simply store their files in the local iFolder directory. Their files are automatically updated to the iFolder server and any other workstations that share the iFolder.
  • Page 16 All that the iFolder owner and iFolder members need is an active network connection and the iFolder client. Novell iFolder provides the following benefits: • Guards against local data loss by automatically backing up local files to the iFolder server and multiple workstations •...
  • Page 17: Enterprise Server Sharing

    1.4 Key Components of iFolder • Section 1.4.1, “iFolder Enterprise Server,” on page 17 • Section 1.4.2, “Novell iFolder 3 Plug-in to Novell iManager 2.5,” on page 18 • Section 1.4.3, “iFolder Web Access,” on page 18 • Section 1.4.4, “The iFolder Client,” on page 18 •...
  • Page 18: Novell Ifolder 3 Plug-In To Novell Imanager 2.5

    1.4.2 Novell iFolder 3 Plug-in to Novell iManager 2.5 The Novell iFolder 3 plug-in to Novell iManager 2.5 is an administrative tool used to manage the iFolder system, user accounts, and user iFolders and data. 1.4.3 iFolder Web Access The iFolder 3.x Web Access server provides an interface to allow users remote access to iFolders on the enterprise server.
  • Page 19: Account Setup For Enterprise Servers

    With an enterprise server, you can synchronize the files at specified intervals or on demand. 1.4.10 Synchronization Log The log displays a log of your iFolder background activity. Overview of Novell iFolder 3.x...
  • Page 20: Ifolder Client Apis

    1.4.11 iFolder Client APIs As part of the iFolder project, APIs are available for the client. For iFolder Client developer documentation, see the iFolder Software Developers Kit (http://forge.novell.com/modules/xfmod/ docman/?group_id=1372). 1.5 What’s Next Before you install iFolder, review the following sections: •...
  • Page 21: What's New

    Novell Novell iFolder 2.1x. This section discusses the following: • Section 2.1, “What’s New in Novell iFolder 3.2 (OES SP2 Linux),” on page 21 • Section 2.2, “What’s New in Novell iFolder 3.1 (OES SP1 Linux),” on page 21 •...
  • Page 22: Comparison Of 2.1X And 3.X Server Features And Capabilities

    • Remote and Policy-Based Administration: Administrators manage iFolder services with the Novell iFolder 3 plug-in to Novell iManager, which is the central management console for Novell Open Enterprise Server. The tool supports policy-based management of the iFolder system, user accounts, and users’ iFolders.
  • Page 23 Feature or Capability Novell iFolder 2.1x Server Novell iFolder 3.x Enterprise Server Automatic provisioning of iFolder services The administrator enables iFolder iFolder automatically provisions services for users, requires users to iFolder users based on LDAP log in to activate the account, and...
  • Page 24 Feature or Capability Novell iFolder 2.1x Server Novell iFolder 3.x Enterprise Server Disk quotas The administrator can specify a The administrator can specify a default user quota that applies default account quota that applies system-wide, and specify individual system-wide, individual user account user quotas for iFolder accounts.
  • Page 25: Comparison Of 2.1X And 3.X Client Features And Capabilities

    2.5 Comparison of 2.1x and 3.x Client Features and Capabilities iFolder Client with a Novell iFolder Feature or Capability Novell iFolder 2.1x Client 3.x Enterprise Server Download location The iFolder download page is...
  • Page 26 Client with a Novell iFolder Feature or Capability Novell iFolder 2.1x Client 3.x Enterprise Server iFolder data stored encrypted on clients iFolder data is stored iFolder data is stored unencrypted on the client. Use unencrypted on the client. Use...
  • Page 27 Client with a Novell iFolder Feature or Capability Novell iFolder 2.1x Client 3.x Enterprise Server Allows the iFolder owner to transfer ownership the iFolder to another user Maximum file size Software limits file size to 4 GB. There are no software...
  • Page 28: Comparison Of 2.1X And 3.X Web Access Features And Capabilities

    Client with a Novell iFolder Feature or Capability Novell iFolder 2.1x Client 3.x Enterprise Server Remote access to iFolder data on Yes, using NetStorage. Yes, using iFolder 3.x Web the server Access Your administrator must configure NetStorage for iFolder services.
  • Page 29 Feature or Capability Novell iFolder 2.1x Web Access Novell iFolder 3.x Web Access Authenticated access Yes, with username and Yes, with username and password authentication via your password authentication via your LDAP server. LDAP server. Encrypted data transfer Yes, with the encrypted iFolder Yes, with HTTPS (SSL) option.
  • Page 30 Novell iFolder 3.x Administration Guide...
  • Page 31: Planning Ifolder Services

    Planning iFolder Services ® ® This section discusses the planning considerations for providing Novell iFolder 3.x services on OES Linux. • Section 3.1, “Security Considerations,” on page 31 • Section 3.2, “Server Workload Considerations,” on page 31 • Section 3.3, “Naming Conventions for Usernames and Passwords,” on page 32 •...
  • Page 32: Naming Conventions For Usernames And Passwords

    LDAP Naming Requirement Usernames and passwords must comply with the constraints set by your LDAP service. For information, see the Novell eDirectory 8.7.3 Administration Guide (http://www.novell.com/ documentation/edir873/treetitl.html). E-Mail Address Naming Requirement If you configure iFolder to authenticate users at login based on their e-mail addresses, make sure that each e-mail address in eDirectory satisfies the following naming requirements: •...
  • Page 33: Admin User Considerations

    The iFolder Admin right can be assigned to other users so that they can also manage iFolder services for the selected server. Use the Administrators page in the Novell iFolder 3 plug-in to add or remove the iFolder Admin right for users. Only users who are in one of the DNs specified in the LDAP Search DN are eligible to be equivalent to the iFolder Admin user.
  • Page 34: Ifolder User Account Considerations

    10,000 and appends it to iFolderProxy. For example, iFolderProxy1234. Initially, the password for the iFolder Proxy user is stored in clear text in the /opt/novell/ ifolder3/etc/simias-server-bootstrap.config file. At the end of the configuration process, the system reboots Apache 2 and starts iFolder. When iFolder runs this first time after configuration, the iFolder process copies the simias-server-bootstrap.config...
  • Page 35: Preventing The Propagation Of Viruses

    You should also enforce client-based virus scanning. For information, see “Configuring Local Virus Scanner Settings for iFolder Traffic” in the iFolder User Guide for Novell iFolder 3.2. 3.5.2 Provisioning User Accounts You can specify any existing containers and groups in the Search DNs field of the iFolder LDAP settings to govern which users are automatically provisioned with accounts for iFolder services.
  • Page 36: Ifolders Data And Synchronization Considerations

    You might include only key file types used for your business, or exclude files that are likely unrelated to business, such as .mp3 files. Novell iFolder 3.x Administration Guide...
  • Page 37: Management Tools

    3.7 Management Tools Use the following tools to manage the Novell iFolder 3.x enterprise server and Web Access server. • Section 3.7.1, “iFolder Configuration Plug-Ins for YaST,” on page 37 •...
  • Page 38: Novell Ifolder 3 Plug-In For Novell Imanager 2.5

    3.7.2 Novell iFolder 3 Plug-In for Novell iManager 2.5 The Novell iFolder 3 plug-in for Novell iManager 2.5 is an administrative tool used to manage the iFolder system, user iFolder accounts, and user iFolders and data. For information about installing iManager, see the Novell iManager 2.5 Installation Guide (http://www.novell.com/documentation/...
  • Page 39: Web Access Configuration File

    3.7.3 Web Access Configuration File Use the /opt/novell/ifolder3/webaccess/Web.config file to configure HTTP runtime parameters for your iFolder Web Access server. For information, see Section 9.4, “Configuring the HTTP Runtime Parameters,” on page Planning iFolder Services...
  • Page 40 Novell iFolder 3.x Administration Guide...
  • Page 41: Coexistence And Migration Issues

    4.1 Coexistence of iFolder 3.x and 2.1x Servers If you use both Novell iFolder 3.x and iFolder 2.1x servers, we recommend that you install each version on its own dedicated server. However, iFolder 3.x enterprise and Web access servers can coexist with an iFolder 2.1x server on an OES Linux computer under the following conditions:...
  • Page 42: Coexistence Of The Ifolder Client With Novell Ifolder 1.X And 2.X Clients

    • You should not attempt to convert the iFolder for Novell iFolder 1.x or 2.x to an iFolder to be managed by Novell iFolder 3.x. Similarly, you should not covert parent folders of that iFolder to a next-generation iFolder.
  • Page 43 3.2. After users have successfully migrated their files to the new system, you can determine the need to maintain a 2.1x server in your environment. Coexistence and Migration Issues...
  • Page 44 Novell iFolder 3.x Administration Guide...
  • Page 45: Prerequisites And Guidelines

    Prerequisites and Guidelines ® ® This section discusses prerequisites and guidelines for this release of Novell iFolder 3.x and the iFolder Client. Before installing and configuring iFolder, make sure that your system meets the requirements in each of the following: •...
  • Page 46: Prerequisites For The Operating System

    Section 5.2.5, “Installing the OES Linux Server,” on page 48 5.2.1 Prerequisites for the Operating System Novell iFolder 3.2 and earlier is designed to work only on the Novell Open Enterprise Server for ® Linux (OES Linux) platform, which is comprised of specific versions of the SUSE Linux Enterprise Server platform and the basic OES applications and services.
  • Page 47: Install Guidelines When Using A Linux Traditional Volume To Store Ifolder Data

    • OES Linux (Minimum predefined server plus graphics support and NSS if desired) • Novell eDirectory 8.7.3 (can be configured on a different OES server) • Novell iManager 2.5 (can be configured on a different OES server) •...
  • Page 48: Installing The Oes Linux Server

    Based on the ECMA/ISO Standards, Mono can run existing programs that target the .NET or Java frameworks. The Mono Project is an open source effort led by Novell and is the foundation for many new applications. For information about Mono, see the Mono Project Web site (http://www.mono-project.com/Main_Page).
  • Page 49: Client Computers

    OES Linux server, uninstall it before you install iFolder. Novell iFolder 3.x supports only the version of Mono included in its install software. If you need to upgrade Mono for another reason, please check our online documentation to see if we explicitly support that version and to learn any necessary steps to make the upgrade work correctly.
  • Page 50 Novell iFolder 3.x Administration Guide...
  • Page 51: Installing And Configuring Ifolder Services

    OES Linux server. The Novell iFolder install modules are available on media for the Support Pack releases of OES Linux. NOTE: If you used the Minimum install option for your OES Linux server, which has no GUI installed, the iFolder services configuration is done with the YaST 2 text-based interface.
  • Page 52 Do one or both of the following, depending on your deployment preferences: • iFolder 3: In the left Selections menu, locate and select Novell iFolder 3, then select its check box to signify that you want to install the RPMs for Novell iFolder 3 and its dependencies.
  • Page 53: Configuring The Ifolder Enterprise Server

    3 Start YaST, click Network Services, then click iFolder 3. 4 Follow the Yast on-screen instructions to proceed through the Novell iFolder 3 configuration. The following table summarizes the decisions you make. IMPORTANT: If you ever need to run the configuration again, you can modify any field except the System Store Path and the iFolder User Login Based on Which LDAP Attribute options.
  • Page 54 Web services user object wwwrun before restarting your web services. At a terminal console prompt, log in as the root user or equivalent, then enter rights -f /media/nss/NSSVOL -r rwfcem trustee wwwrun.ou.o.treename Novell iFolder 3.x Administration Guide...
  • Page 55: Configuring The Ifolder Web Access Server

    6e Start Apache by entering either of the following commands at the prompt: /etc/init.d/apache2 start rcapache2 start 7 Go to Novell iManager to install the Novell iFolder 3 plug-in or to manage iFolder services. For information, see Installing the Novell iFolder 3 Plug-In for iManager.
  • Page 56 For information, see Section 9.4, “Configuring the HTTP Runtime Parameters,” on page 7 If it is not already installed, go to Novell iManager to install the Novell iFolder 3 plug-in or to manage iFolder services. For information, see Installing the Novell iFolder 3 Plug-In for iManager.
  • Page 57: Installing The Novell Ifolder 3 Plug-In For Imanager

    Section 6.4.3, “Installing a Plug-In When RBS Is Configured,” on page 58 6.4.1 Prerequisites Novell iManager 2.5 If you have not already done so, install Novell iManager 2.5 on the same or different server as your iFolder server. For information, see Novell iManager 2.5 Installation Guide (http:// www.novell.com/documentation/imanager25/imanager_install_25/data/hk42s9ot.html)
  • Page 58: Installing A Plug-In When Rbs Is Not Configured

    2 In the toolbar, click the Configure icon (person seated behind a desk). 3 In Roles and Tasks, expand Module Installation, then click Available Novell Plug-In Modules. 4 Locate the iFolder iManager Module plug-in, select its plug-in check box, then click Install.
  • Page 59: Accessing Imanager And The Novell Ifolder 3 Plug-In

    6.5 Accessing iManager and the Novell iFolder 3 Plug-In The Novell iFolder 3 plug-in to Novell iManager 2.5 is the tool used to manage your iFolder server. For information, see Section 6.4, “Installing the Novell iFolder 3 Plug-In for iManager,” on page 1 Open a Web browser to the iManager Login page by entering the following location: http://servername.example.com/nps/iManager.html...
  • Page 60: Provisioning Users And Ifolder Services

    For information, see Section 8.2, “Connecting to the iFolder Server,” on page Novell iFolder 3.x opens to the System Management page, which consists of a tabbed list of the main administrative functions that can be performed on iFolder. 6.6 Provisioning Users and iFolder Services After you configure your Novell iFolder 3.x enterprise server, you must specify containers and...
  • Page 61: Prerequisites

    All users in the containers and groups listed in the iFolder LDAP settings’ Search DN field are automatically provisioned as iFolder users. 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select LDAP to open the System page to the LDAP tab, then click Modify.
  • Page 62: Synchronizing The List Of Provisioned Users With The Ldap Directory

    6.6.3 Synchronizing the List of Provisioned Users with the LDAP Directory 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select LDAP to open the System page to the LDAP tab, then click Modify.
  • Page 63: Accessing The Ifolder 3.X Welcome Page

    2 In the left navigator, click iFolder 3.x to open the iFolder 3.x Welcome page. 6.7.3 Downloading the iFolder Client On the iFolder 3.x Welcome page, users can select one of the following client links to download the install files for the iFolder client for Novell iFolder 3.x: Link Name Operating System Filename iFolder 3.x Linux Client...
  • Page 64: Installing The Ifolder Client

    6.9 Updating Mono for the Server and Client Novell iFolder 3.x supports only the version of Mono included in the install software. The iFolder client for Linux or Macintosh supports only the version of Mono included in the install software for those platforms.
  • Page 65: Uninstalling The Ifolder 3.X Enterprise Server

    IP address for the iFolder account has not changed. Users must also set up iFolders and share relationships again. 6.11 What’s Next You have now installed and configured your Novell iFolder 3.x enterprise server and provisioned iFolder services for users. To set up system policies for iFolder services, continue with Chapter 8, “Managing iFolder Services,”...
  • Page 66 Novell iFolder 3.x Administration Guide...
  • Page 67: Managing An Ifolder Enterprise Server

    Managing an iFolder Enterprise Server ® ® This section describes how to manage your Novell iFolder 3.x enterprise server on Novell Open Enterprise Server platform. • Section 7.1, “Starting iFolder Services,” on page 67 • Section 7.2, “Stopping iFolder Services,” on page 67 •...
  • Page 68: Managing The Simias Log And Simias Access Log

    <maxSizeRollBackups retain log files that are kept before they value="10" /> are overwritten. The log rolls over <maxSizeRollBackups sequentially until the maximum value=”number” /> number of backups are created, then overwrites the oldest log file. Novell iFolder 3.x Administration Guide...
  • Page 69: Backing Up The Ifolder Server

    1 Stop the iFolder server by entering the following command as root user: /etc/init.d/apache2 stop 2 Use your normal file system backup procedures to back up the following data: • Simias store directory The default location is /var/opt/novell/ifolder3/simias. • Simias configuration file The default locations are /var/lib/wwwrun/.local/share/simias/ Simias.config or /home/wwwrun/.local/share/simias/ Simias.config.
  • Page 70: Backing Up The Ifolder Store With The Tsaif

    /etc/init.d/apache2 start 7.6 Backing Up the iFolder Store with the TSAIF The Target Service Agent (TSA) for Novell iFolder 3.x supports the back up of the iFolder store. • Section 7.6.1, “Understanding TSAIF,” on page 70 • Section 7.6.2, “Syntax,” on page 71 •...
  • Page 71: Syntax

    iFolder TSA Granularity TSAIF supports creating archives that contain the following: • The entire iFolder store • All iFolders owned by a specified Domain member • An individual iFolder TSAIF supports restoring the following: • The entire iFolder store • All iFolders owned by a specified Domain member •...
  • Page 72 The name of the Collection or Collection owner can be obtained by stripping off the pattern ".????????-????-????-????-????????????" from the first two components of the path TSAIF returns to the backup application. Novell iFolder 3.x Administration Guide...
  • Page 73: Ifolder Path Examples

    7.6.4 iFolder Path Examples The following examples show how to use iFolder paths to backup and restore data at different levels in the iFolder store. Back up or restore the entire iFolder store. /myOwner.12345678-1234-1234-1234-123456789abc Back up or restore all Collections owned by myOwner. /myOwner.12345678-1234-1234-1234-123456789abc/myCollection.22345678- 1234-1234-1234-123456789abc Back up or restore the Collection named myCollection.
  • Page 74: Tsaif And Smsconfig Examples

    Stores the full paths for both directories and files in the created archive. Does not overwrite existing files while extracting files from -k, --keep-old-files the archive. Files are overwritten if this option is not present. Backs up files newer than date. -N, --after-date=date Novell iFolder 3.x Administration Guide...
  • Page 75: Tsaif And Nbackup Examples

    Option Command The password to connect to the TSA. The password can be -P, --password=password supplied at runtime. Connects to the file system TSA of the host specified in -R, --remote-target=hostname hostname for backup. Use with the --target-type option. Connects to the TSA specified by target_name, where --target-type=target_name the target name is Linux, NetWare, or iFolder.
  • Page 76: Additional Information

    -xvf owner.sidf -U root -P password --target-type=ifolder --extract-dir=/owner/collection/relative-path nbackup -xvf full.sidf -U root -P 7.6.9 Additional Information For more information about backup, see the following man pages on your iFolder enterprise server: nbackup(1), sms(7), smdrd(8), smsconfig(1), tsaif.conf(5). Novell iFolder 3.x Administration Guide...
  • Page 77: Recovering From A Catastrophic Loss Of The Ifolder Server

    2 Stop the iFolder server by entering the following command as root user: /etc/init.d/apache2 stop 3 Remove the following corrupted data: • Simias store directory The default location is /var/opt/novell/ifolder3/simias. • Simias configuration file The default locations are /var/lib/wwwrun/.local/share/simias/ Simias.config or /home/wwwrun/.local/share/simias/ Simias.config.
  • Page 78: Recovering Individual Files Or Directories

    • Other files or directories in the iFolder 2 Open a Web browser to iManager, then log in with your Admin username and password. 3 Under Roles and Tasks, expand Novell iFolder 3, select iFolders, then wait for the page to refresh.
  • Page 79: Moving Ifolder Data From One Ifolder Server To Another

    2 Stop iFolder services. As a root user, enter the following command at the terminal console: /etc/init.d/apache2 stop 3 Use your normal file system backup procedures to back up the following data: • Simias store directory The default location is /var/opt/novell/ifolder3/simias. • Simias configuration file The default locations are /var/lib/wwwrun/.local/share/simias/ Simias.config or /home/wwwrun/.local/share/simias/ Simias.config.
  • Page 80 Novell iFolder 3.x Administration Guide...
  • Page 81: Managing Ifolder Services

    Section 8.7, “Securing Enterprise Server Communications,” on page 94 8.1 Accessing the Novell iFolder 3 Plug-In for iManager Use the Novell iFolder 3 plug-in for Novell iManager 2.5 to manage the iFolder system, user accounts, and iFolders. For information about iManager, see the Novell iManager 2.5 Administration Guide (http://www.novell.com/documentation/imanager25/imanager_admin_25/...
  • Page 82: Connecting To The Ifolder Server

    If you are not logged in to an iFolder server, whenever you click a task under the Novell iFolder 3 role, the Connection page opens to allow you to log in to the iFolder enterprise server you want to manage.
  • Page 83: Viewing General System Information

    8.3 Viewing General System Information 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. By default, the System option opens to the General tab on the Systems page.
  • Page 84: Configuring The Ldap Settings For An Ifolder Server

    Server Use the LDAP Settings page to manage LDAP Settings for your iFolder server. In iManager, expand the Novell iFolder 3 role, then select System > LDAP to open the System page to the LDAP tab. • Section 8.4.1, “Viewing the Current LDAP Settings,” on page 84 •...
  • Page 85: Modifying The Ifolder Ldap Settings

    Time 8.4.2 Modifying the iFolder LDAP Settings 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select LDAP to open the System page to the LDAP tab, then click Modify.
  • Page 86 Synchronize option on the LDAP Settings page to synchronize the iFolder user list on demand and verify your new Proxy user settings. (In iManager, expand the Novell iFolder 3 role, select Systems, select the LDAP tab, then click Update and Synchronize Now.)
  • Page 87 Parameter Description Proxy User Specify the password twice, then click OK to update the password stored in the Password LDAP Settings. Whenever you modify the Proxy User DN, you must also specify the password associated with the new iFolder Proxy user. The password is used to authenticate the iFolder Proxy user to the LDAP server when iFolder synchronizes users for the iFolder user list.
  • Page 88: What To Do If The Ifolder Admin User Is Deleted From Ldap

    2 Modify the iFolder Proxy user password in its eDirectory object. 2a In Roles and Tasks, expand the eDirectory Users role, then click Modify User. 2b Specify the iFolder Proxy user in DN format or browse to locate the user object, then click Novell iFolder 3.x Administration Guide...
  • Page 89: Synchronizing The Ifolder User List With The Ldap Server

    LDAP Settings page opens. 4 Verify that the password in LDAP settings matches the password in eDirectory. In iManager Roles and Tasks, expand the Novell iFolder 3 role, select Systems, select the LDAP tab, then click Update and Synchronize Now.
  • Page 90: Configuring System Policies

    8.5 Configuring System Policies Use the System Policies page to manage system-wide policies. In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select System > Policy to open the System page to the Policy tab. •...
  • Page 91: Modifying Ifolder System Policies

    When the time elapses, another session is started. 8.5.2 Modifying iFolder System Policies 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select Policy to open the System page to the Policy tab, then click Modify.
  • Page 92 • The local machine policy, or the setting on the client machine synchronizing with the server. • The iFolder (collection) policy. Novell iFolder 3.x Administration Guide...
  • Page 93: Configuring Ifolder Administrators

    Repeat the following process for each user who you want to become an iFolder Admin user: 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select Administrators to view a list of users with the iFolder Admin right.
  • Page 94: Securing Enterprise Server Communications

    Admin user: 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select Administrators to view a list of users with the iFolder Admin right.
  • Page 95: Configuring The Ssl Cipher Suites For The Apache Server

    SSL. 1 In iManager, expand the Novell iFolder 3 role, select System, then wait for the page to refresh. 2 Select LDAP to open the System page to the LDAP tab, then click Modify.
  • Page 96: Configuring The Enterprise Server For Ssl Communications With The Ifolder Client

    To modify the setting, edit the SSL parameters in the appSettings section of the /opt/ novell/ifolder3/web/web.config file on the enterprise server. To configure secure Web traffic with SSL, modify the value of SimiasRequireSSL to Yes and the SimiasSSLPort to 443. For example: <appSettings>...
  • Page 97: Managing An Ifolder Web Access Server

    Managing an iFolder Web Access Server ® ® This section describes how to manage your Novell iFolder 3.x Web Access server on Novell Open Enterprise Server. • Section 9.1, “Starting iFolder Web Access Services,” on page 97 • Section 9.2, “Stopping iFolder Web Access Services,” on page 97 •...
  • Page 98 The Execution Time-Out and Maximum Request Length parameters must be configured with compatible settings in the /opt/novell/ifolder3/web/web.config file for the iFolder enterprise server and in the /opt/novell/ifolder3/webaccess/Web.config file for the Web Access server. The settings in Web.config for the enterprise server must be the same size or larger than the settings in ../webaccess/Web.config for the Web Access server.
  • Page 99: Securing Web Access Server Communications

    <httpRuntime executionTimeout="300" maxRequestLength="5120" /> If the ../webaccess/Web.config values exceed the values in ../web/web.config for the enterprise server, you must also increase the sizes of runtime parameters in that file. 9.5 Securing Web Access Server Communications This section describes how to configure SSL traffic between the iFolder Web Access server and other components.
  • Page 100: Configuring The Web Access Server For Ssl Communications With The Enterprise

    SSL (HTTPS) communications between the servers. Traffic between the two servers is secure. If you specify an http:// in the URL, HTTP is used for communications between the servers and traffic is insecure. The setting is stored in the /opt/novell/ifolder3/webaccess/Web.config file under the following tag: <add key="SimiasUrl"...
  • Page 101: Configuring The Web Access Server For Ssl Communications With Web Browsers

    IMPORTANT: Do not disable SSL on the Web Access server if the two servers are on different machines. If the two servers are running on the same machine and you want to disable SSL, rerun the YaST configuration, and specify http://localhost as the URL for the enterprise server. For information, see Section 6.3, “Configuring the iFolder Web Access Server,”...
  • Page 102 102 Novell iFolder 3.x Administration Guide...
  • Page 103: Managing Ifolder Users

    Server,” on page 10.2 Searching for a User Account 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select Users to go to the User Search page. 2 Select a name criterion (User Name, First Name, Last Name).
  • Page 104: Viewing General User Account Information

    Section 10.4.2, “Modifying User Account Policies,” on page 106 10.4.1 Viewing the Current User Account Policies 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, select Users, then wait for the page to refresh to view a list of current iFolder users.
  • Page 105 Parameter Description Space Limit Specifies the maximum total space (in MB) that a user’s iFolder data is allowed to use, across all iFolders the user owns. A user quota supersedes a system- wide quota, whether the user quota is larger or smaller than the system-wide quota.
  • Page 106: Modifying User Account Policies

    10.4.2 Modifying User Account Policies 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, select Users, then wait for the page to refresh to view a list of current iFolder users. 2 Click the link for the user’s name to open the User page for that user account.
  • Page 107: Enabling And Disabling Ifolder User Accounts

    The user cannot log in and, therefore, cannot synchronize (up or down) any data until the account is again enabled. 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select Enable/Disable Users Account.
  • Page 108 108 Novell iFolder 3.x Administration Guide...
  • Page 109: Managing Ifolders

    Section 11.1.2, “Creating an iFolder from the User Page,” on page 110 11.1.1 Creating an iFolder from the iFolders Page 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select iFolders. 2 Click New to open the Create an iFolder dialog box.
  • Page 110: Creating An Ifolder From The User Page

    11.1.2 Creating an iFolder from the User Page 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select Users. 2 Search for and select the Name of the user you want to manage, then click OK.
  • Page 111: Viewing Information About An Ifolder

    11.3 Viewing Information about an iFolder In iManager, select the Novell iFolder role, then select iFolders or Orphaned iFolders, locate the iFolder you want to manage, then click the iFolder’s Name link to open the iFolder management page to the General tab.
  • Page 112: Sharing An Ifolder

    After the user accepts the invitation and sets up the iFolder, the user shows up in the member list. However, if you add the user 112 Novell iFolder 3.x Administration Guide...
  • Page 113: Adding A Member

    Section 11.5.3, “Removing a Member,” on page 114 11.5.1 Adding a Member 1 In iManager, expand the Novell iFolder 3 role, then select iFolders or Orphaned iFolders. 2 Locate the iFolder you want to manage, then click the iFolder’s Name link to open the iFolder management page to the General tab.
  • Page 114: Removing A Member

    Wait for the page to refresh. The user’s icon should reflect the new access right. 11.5.3 Removing a Member 1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select iFolders or Orphaned iFolders. 114 Novell iFolder 3.x Administration Guide...
  • Page 115: Deleting An Ifolder

    11.6 Deleting an iFolder 1 In iManager Roles and tasks, expand the Novell iFolder 3 role, then select Users. 2 Search for and select the user you want to manage, then click OK.
  • Page 116: Enabling And Disabling Synchronization For An Ifolder

    1 In iManager Roles and Tasks, expand the Novell iFolder 3 role, then select Orphaned iFolders. 2 Browse to locate the orphaned iFolder you want to manage, then select the check box next to the iFolder.
  • Page 117: A Configuration Files

    <setting name="EnterpriseDescription" value="20050525 Build 1" /> <setting name="AdminDN" value="cn=iFolderAdmin,o=acme" /> <setting name="Encoding" value="iso-8859-1" /> <setting name="EnterpriseID" value="76c8cfd1-f876-4bc5-b7fd-beb5119c870d" /> </section> <section name="StoreProvider"> <setting name="Path" value="/var/opt/novell/ifolder3" /> <setting name="Assembly" value="Simias.dll" /> <setting name="Type" value="Simias.Storage.Provider.Flaim.FlaimProvider" /> <setting name="Version" value="0.2" /> </section> <section name="LdapAuthentication">...
  • Page 118: Web.config File For The Enterprise Server

    <setting name="ConcurrentClients" value="64" /> </section> </configuration> A.2 Web.config File for the Enterprise Server By default, the web.config file for the enterprise server is in the /opt/novell/ifolder3/ web directory. The following is an example of a configured file. <?xml version="1.0" encoding="utf-8"?> <configuration>...
  • Page 119 <!-- Enable this if you want gzip compression. Also uncomment the <mono.aspnet> section below <configSections> <sectionGroup name="mono.aspnet"> <section name="acceptEncoding" type="Mono.Http.Configuration.AcceptEncodingSectionHandler, Mono.Http, Version=1.0.5000.0, PublicKeyToken=0738eb9f132ed756" /> </sectionGroup> </configSections> --> <system.web> <customErrors mode="Off"/> <httpRuntime executionTimeout="180" maxRequestLength="1048576" /> <!-- take this out until we need it <webServices>...
  • Page 120: Web.config File For The Web Access Server

    <add key="Enterprise" value="True" /> </appSettings> </configuration> A.3 Web.config File for the Web Access Server By default, the Web.config file for the Web Access server is in the /opt/novell/ ifolder3/webaccess/ directory. The following is an example of a configured file. <?xml version="1.0" encoding="utf-8"?> <configuration>...
  • Page 121 only when debugging and to false at all other times. For more information, refer to the documentation about debugging ASP.NET files. --> <compilation defaultLanguage="C#" debug="true" /> <!-- CUSTOM ERROR MESSAGES Set customErrors mode="On" or "RemoteOnly" to enable custom error messages, "Off" to disable. Add <error>...
  • Page 122 By default ASP.NET uses cookies to identify which requests belong to a particular session. If cookies are not available, a session can be tracked by adding a session identifier to the URL. To disable cookies, set 122 Novell iFolder 3.x Administration Guide...
  • Page 123 sessionState cookieless="true". --> <sessionState mode="InProc" cookieless="false" timeout="30" /> <!-- GLOBALIZATION This section sets the globalization settings of the application. --> <globalization requestEncoding="utf-8" responseEncoding="utf-8" /> </system.web> <appSettings> <add key="SimiasUrl" value="https://localhost" /> <add key="SimiasCert" value="a_certification_key_goes_here" /> </appSettings> <location path="Default.aspx"> <system.web> <authorization> <allow users="*" /> </authorization>...
  • Page 124 124 Novell iFolder 3.x Administration Guide...
  • Page 125: B Clustering Ifolder 3.X Servers With Novell Cluster Services For Linux

    3.x Services,” on page 125. 2 Install and configure Novell Cluster Services (NCS) on the OES Linux servers you plan to use in the iFolder 3.x cluster. IMPORTANT: Do not create a Cluster Resource at this time; it is configured after you set up iFolder services on the cluster.
  • Page 126: Configuring Ifolder 3.X Services On An Ncs For Linux Cluster

    B.3 Configuring iFolder 3.x Services on an NCS for Linux Cluster The following procedure describes how to configure Novell iFolder 3.x services on an NCS for Linux cluster. You can optionally add iFolder 3.x Web Access services to the cluster.
  • Page 127 In the following commands, replace /mnt/ifolder3 with the mount point of the shared volume you created in Step 5a Mount the shared volume. At a terminal console, enter Clustering iFolder 3.x Servers with Novell Cluster Services for Linux 127...
  • Page 128 If the link appears blue, it is valid. If the link appears red, the link is invalid. 5h Change ownership of the .local symbolic link to user wwwrun and group www. At a server console, enter chown -R wwwrun:www /var/lib/wwwrun/.local 5i Unmount the shared volume. At the server console, enter 128 Novell iFolder 3.x Administration Guide...
  • Page 129: Creating The Ifolder 3.X Cluster Resource

    5 Enter the name of the resource you want to create, such as iFolder3. Do not use periods in cluster resource names. Novell clients interpret periods as delimiters. If you use a space in a cluster resource name, that space is converted to an underscore.
  • Page 130: Nss File System

    ##MYVOL is the name of your NSS volume nss /poolactivate=MYPOOL exit_on_error nssmount -n MYVOL #add the IP address ##xx.xx.xx.xx is your ’highly available’ IP address exit_on_error add_secondary_ipaddress xx.xx.xx.xx # start the service exit_on_error /etc/init.d/apache2 start #return status exit 0 ################################################### 130 Novell iFolder 3.x Administration Guide...
  • Page 131: Sample Unload Scripts For Ifolder 3.X Clusters

    ##### NSS File System Sample Unload Script #################### #!/bin/bash . /opt/novell/ncs/lib/ncsfuncs #request service stop ignore_error /etc/init.d/apache2 stop #del the IP address ##xx.xx.xx.xx is your ’highly available’ IP address ignore_error del_secondary_ipaddress xx.xx.xx.xx Clustering iFolder 3.x Servers with Novell Cluster Services for Linux 131...
  • Page 132: Troubleshooting

    10 ignore_error fuser -k /$MOUNT-POINT sleep 5 Replace /$MOUNT-POINT with the actual path of the mount point of your iFolder data store. For example, if the mount point is /var/opt/novell/ifolder3/data, add: #stop service otherwise sleep 10 ignore_error fuser -k /var/opt/novell/ifolder3/data...
  • Page 133: C Managing Ssl Certificates For Apache

    Managing SSL Certificates for Apache ® ® This section discusses how to acquire and manage SSL certificates for your Novell iFolder servers. • Section C.1, “Generating an SSL Certificate for the Server,” on page 133 • Section C.2, “Generating a Self-Signed SSL Certificate for Testing Purposes,” on page 134 •...
  • Page 134: Generating A Self-Signed Ssl Certificate For Testing Purposes

    4 Generate the self-signed certificate (.cert file), using the private key (filename.key) you created in Step 2 and the certificate-signing request (filename.csr) you created in Step 3. At a terminal console, enter openssl x509 -req -days 30 -in filename.csr -signkey filename.key -out filename.cert 134 Novell iFolder 3.x Administration Guide...
  • Page 135: Configuring Apache To Point To An Ssl Certificate On An Ifolder Server

    For information about configuring Apache to point to the self-signed certificate, see the following: • Section C.3, “Configuring Apache to Point to an SSL Certificate on an iFolder Server,” on page 135 • Section C.4, “Configuring Apache to Point to an SSL Certificate on a Shared Volume for an iFolder Cluster,”...
  • Page 136 ) to point to the .key file and .cert file on the shared volume by modifying the values for the following parameters: SSLCertificateKeyFile=/mnt/ifolder3/sharedkey/filename.key SSLCertificateFile=/mnt/ifolder3/sharedkey/filename.cert Replace the path to the files with the actual location and filename on the shared volume. 4 Unmount the shared volume. At a terminal console, enter umount /mnt/ifolder3 136 Novell iFolder 3.x Administration Guide...
  • Page 137: Version History

    For information, see Section 2.3, “What’s New in Novell iFolder 3.0 (OES Linux),” on page Server is supported for Novell Open Enterprise Server on Linux servers. The client supports Linux, Windows, and Macintosh desktops. Bundled Adds support for OES SP1 Linux servers and repairs known defects. For information, see Section 2.2, “What’s New in Novell iFolder 3.1 (OES SP1 Linux),”...
  • Page 138: Directory Services Support

    D.5 Web Server Support Web Server Apache 2 (worker mode) 2 (worker mode) 2 (worker mode) D.6 iFolder User Access Support iFolder User Access Method iFolder client iFolder client, using a proxy 138 Novell iFolder 3.x Administration Guide...
  • Page 139: Management Tools Support

    User Access Method Novell iFolder 3.x Web IE 6.0 IE 6.0 IE 6.0 Access Firefox Firefox Firefox Safari (Macintosh) Safari (Macintosh) Safari (Macintosh) D.7 Management Tools Support iFolder Management Interfaces iFolder 3 plug-in to iManager 2.5 iFolder 3 plug-in to YaST...
  • Page 140 140 Novell iFolder 3.x Administration Guide...
  • Page 141: E Documentation Updates

    Refer to the publication date, which appears on the front cover and the Legal Notices page, to determine the release date of this guide. For the most recent version of the Novell iFolder 3.x Administration Guide, see the Novell iFolder 3.x documentation Web site (http://www.novell.com/...
  • Page 142: Managing An Ifolder Enterprise Server

    The user and the iFolder will show up in the Web access interface without the user setting up a local iFolder on his or her computer. E.1.4 Clustering iFolder 3.x Servers with Novell Cluster Services for Linux The following changes were made to this section:...
  • Page 143: Managing The Ssl Certificate For The Apache Web Server

    Change Section D.4, “Workstation The iFolder 3.4 client was released only for the SUSE Linux Enterprise Operating Systems Support Desktop 10 operating system. It is compatible with Novell iFolder 3.2 for the iFolder Client,” on servers. page 138 E.2 May 24, 2006 Updates were made to the following section.
  • Page 144: What's New

    For example, if a user named John Smith has a common name of jsmith and e-mail of john.smith@example.com, this field determines whether the user enters jsmith or john.smith@example.com as the Username when logging in to the iFolder server. 144 Novell iFolder 3.x Administration Guide...
  • Page 145: Managing Ifolder Services

    Change Section D.7, “Management This section is new. Tools Support,” on page 139 E.4 August 19, 2005 (Novell iFolder 3.1 for OES SP1 Linux) Updates were made to the following sections. The changes are explained below. • Section E.4.1, “What’s New,” on page 146...
  • Page 146: What's New

    Section E.4.6, “Managing an iFolder Enterprise Server,” on page 147 • Section E.4.7, “Managing iFolder Services,” on page 147 • Section E.4.8, “Clustering iFolder 3.x with Novell Cluster Services for Linux,” on page 147 • Section E.4.9, “Managing SSL Certificates for Apache,” on page 148 •...
  • Page 147: Installing And Configuring Ifolder Services

    Section 8.4.4, “Securing This section is new. Access to the iFolder Proxy User Password,” on page 88 Multiple locations Edits were made for clarity. E.4.8 Clustering iFolder 3.x with Novell Cluster Services for Linux This section is new. Documentation Updates 147...
  • Page 148: Managing Ssl Certificates For Apache

    E.4.9 Managing SSL Certificates for Apache This section is new. E.4.10 Product History of iFolder 3.x This section is new. 148 Novell iFolder 3.x Administration Guide...

This manual is also suitable for:

Ifolder 3.x

Table of Contents