19.1.2 Tree Admin is Not Automatically Granted Rights for
DSfW Administration
When you install DSfW in a child domain or grandchild domain, the tree admin identity is not
automatically added as an administrator of services on the server unless the tree admin is the identity
used during the install. If a different identity is used for installation, the tree admin cannot manage
the DSfW services on that server.
The administrator credentials that you entered during the DSfW install are automatically configured
to allow that user to manage DSfW and related services on the server. After the install, you can add
another administrator by configuring the following for the user:
Give the user the Supervisor right to the Server object
Linux-enable the user with Linux User Management by adding the user to the LUM-enabled
Domain admingroup associated with the server.
This applies to any administrator that you want to manage DSfW on that server.
19.1.3 DSfW Services Stop Working if the Concurrent LDAP
Bind Limit is Set to 1
This is an invalid scenario.
If you set the bind limit to 1, services such as kinit, rpcclient, SASL-BIND, and Samba, stop and you
cannot join a workstation. For the services to function as expected, change the LDAP bind limit to 0,
which is the default.
19.1.4 The Provision Utility Succeeds Only With the --locate-dc
Option
By default, the Provision utility runs with the
with the following message:
Failed to establish LDAP connection with <domain name> : Unknown
authentication method.
To execute other options, export
valid domain username before using Provision utility. All the options will work.
19.1.5 Users Are Not Samified When the RID Master Role is
Seized
When the current RID master is down, the users already added to the servers other than DSfW after
the RID pools are exhausted are not samified.
To resolve this issue, run
provision_samify.pl
--locate-dc
SASL_PATH=/opt/novell/xad/lib/sasl2
/opt/novell/xad/share/dcinit/provision/
on the DSfW server.
option only. For other options, it fails
and
kinit
with a
Troubleshooting 207
Need help?
Do you have a question about the OPEN ENTERPRISE SERVER 2.0 SP2 - DOMAIN SERVICE FOR WINDOWS and is the answer not in the manual?
Questions and answers