Red Hat NETSCAPE DIRECTORY SERVER 6.2 - DEPLOYMENT Installationsanleitung

Stöbern Sie online oder laden Sie Installationsanleitung nach Server Red Hat NETSCAPE DIRECTORY SERVER 6.2 - DEPLOYMENT herunter. Red Hat NETSCAPE DIRECTORY SERVER 6.2 - DEPLOYMENT Installation guide Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 137
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Installation Guide

Ella Deon Lackey Red Hat Directory Server 8.0Installation Guidefor installation and upgradeEdition 8.0.5

Seite 2 - Edition 8.0.5

WARNINGA warning indicates potential data loss, as may happen when tuning hardware for maximumperformance.2. Additional ReadingThe Directory Server Ad

Seite 3

WARNINGIf Directory Server databases have been moved from their default location (/opt/redhat-ds/slapd-instancenam e/db), migration will not copy thes

Seite 4 - Table of Contents

Table 8.1. migrate-ds-admin OptionsOption Alternate Options DescriptionGeneral.ConfigDirectoryAdminPwd=passwordRequired. This is the passwordfor the c

Seite 5

the Directory Server is beingmigrated from one machine toanother with a differentarchitecture. For cross-platformmigrations, only certain data aremigr

Seite 6

parameters are only taken from the old instance. It is not possible to change the configuration settings,such as the hostname or port, using the migra

Seite 7

The migration script has different options available to facilitate migration; the different usage scenariosare explained in the following sections.Sec

Seite 8 - 1. Examples and Formatting

1. Stop all old Directory Server instances and the Administration Server.2. Back up all the Directory Server user and configuration data.3. On the

Seite 9

WARNINGIf Directory Server databases have been moved from their default location (/opt/redhat-ds/slapd-instancenam e/db), migration will not copy thes

Seite 10 - 3. Giving Feedback

8.4.3. Migrating a Directory Server from One Machine to AnotherTo migrate a Directory Server installation from one machine to a new Directory Server i

Seite 11 - 4. Document History

The m igrate-ds-adm in command automatically migrates every Directory Server instance configured.As with migrating Directory Server on the same machin

Seite 12 - 1.2.1. Port Numbers

# /usr/sbin/migrate-ds-admin.pl --cross --oldsroot server2:/migration/opt/redhat-ds --actualsroot /opt/redhat-ds General.ConfigDirectoryAdminPwd

Seite 13

4. Document HistoryRevision 8.0.5 January 11, 2010 Ella Deon Lackey Adding [slapd] directives per Bugzilla #500475.Revision 8.0.4 September 9, 2009 E

Seite 14 - 1.2.3. Directory Manager

access control listSee ACL.access right sIn the context of access control, specify the level of access granted or denied. Access rightsare related to

Seite 15 - 1.2.8. Administration Domain

also follows a standard syntax for the type of information that can be stored as the attributevalue.attribute listA list of required and optional attr

Seite 16

branch entryAn entry that represents the top of a subtree in the directory.browserSoftware, such as Mozilla Firefox, used to request and view World Wi

Seite 17

changelogA changelog is a record that describes the modifications that have occurred on a replica. T hesupplier server then replays these modification

Seite 18

called a consumer for that replica.CoSA method for sharing attributes between entries in a way that is invisible to applications.CoS definition entryI

Seite 19 - 1.4. Overview of Setup

Directory ManagerThe privileged database administrator, comparable to the root user in UNIX. Access controldoes not apply to the Directory Manager.dir

Seite 20 - Parameters”

ent ry distributionMethod of distributing directory entries across more than one server in order to scale tosupport large numbers of entries.ent ry ID

Seite 21

hostnameA name for a machine in the form machine.domain.dom, which is translated into an IP address.For example, www.exam ple.com is the machine www

Seite 22

Int ernational Standards OrganizationSee ISO.IP addressAlso Internet Protocol address. A set of numbers, separated by dots, that specifies the actuall

Seite 23

LDIFLDAP Data Interchange Format. Format used to represent Directory Server entries in text form.leaf entryAn entry under which there are no other ent

Seite 24

Chapter 1. Preparing for a Directory Server InstallationBefore you install Red Hat Directory Server 8.0, there are required settings and information t

Seite 25 - 2.1. Hardware Requirements

MD5A message digest algorithm by RSA Data Security, Inc., which can be used to produce a shortdigest of data that is unique with high probability and

Seite 26 - 2.2.1. Using dsktune

Allows the creation of roles that contain other roles.net work management applicat ionNetwork Management Station component that graphically displays

Seite 27

requested.Pparent accessWhen granted, indicates that users have access to entries below their own in the directory treeif the bind DN is the parent of

Seite 28

protocol data unitSee PDU.proxy authenticat ionA special form of authentication where the user requesting access to the directory does notbind with it

Seite 29 - 2.2.3. HP-UX 11i

A replica that contains a master copy of directory information and can be updated. A server canhold any number of read-write replicas.referential inte

Seite 30

role-based att ributesAttributes that appear on an entry because it possesses a particular role within an associatedCoS template.rootThe most privileg

Seite 31

Server SelectorInterface that allows you select and configure servers using a browser.server serviceA process on Windows that, once running, listens f

Seite 32 - 2.2.4. Sun Solaris 9

SNMP subagentSoftware that gathers information about the managed device and passes the information to themaster agent. Also called a subagent.SSLA sof

Seite 33

symmetric encryptionEncryption that uses the same key for both encrypting and decrypting. DES is an example of asymmetric encryption algorithm.system

Seite 34

A unique number associated with each user on a Unix system.URLUniform Resource Locater. The addressing system used by the server and the client to req

Seite 35

NOTEWhile the legal range of port numbers is 1 to 65535, the Internet Assigned Numbers Authority(IANA) has already assigned ports 1 to 1024 to common

Seite 36

Configuration direct ory, Configuration Direct oryCustom setup- HP-UX 11i, Custom Setup- Red Hat Enterprise Linux, Custom Setup- Solaris, Custom Setup

Seite 37 - Enterprise Linux

- starting and stopping, Starting and Stopping Directory Server- starting the Console, Starting the Directory Server Console- uninstalling Directory S

Seite 38 - 3.1. Installing the JRE

HP-UX 11i, Sett ing up Red Hat Direct ory Server on HP-UX 11i- custom setup, Custom Setup- express setup, Express Setup- installing Directory Server p

Seite 39 - 3.3. Express Setup

JRE- HP-UX 11i, Installing the JRE- Red Hat Enterprise Linux, Installing the JRE- Solaris, Installing the JREMMigrat ing, Migrating from Previous Vers

Seite 40 - # /usr/sbin/setup-ds-admin.pl

- HP-UX, HP-UX Patches- Red Hat Enterprise Linux, Red Hat Enterprise Linux Patches- Solaris, Solaris PatchesPerl- HP-UX, Perl Prerequisites- Red Hat E

Seite 41

Re-registering Directory Server Instances- registering Directory Server with Configuration Directory Server, Registering anExisting Directory Server I

Seite 42 - 3.4. Typical Setup

- required patches, Solaris Patches- system configuration, Solaris System Configuration- DNS and NIS, DNS and NIS Requirements- File descriptors, File

Seite 43 - System Group [nobody]:

UUninst alling Directory Server- HP-UX, HP-UX- Red Hat Enterprise Linux, Linux- Solaris, SolarisRed Hat Directory Server 8.0 Installation Guide134

Seite 44

Listening to Restricted Ports as Unprivileged UsersEven though port numbers less than 1024 are restricted, the LDAP server can listen to port 389 (and

Seite 45 - 3.5. Custom Setup

IMPORTANTThe default Administration Server user is the same as the Directory Server user, which is nobody. If the Administration Server is given a dif

Seite 46

has complete access to all installed Directory Servers, regardless of the domain.Servers on two different domains can use different user directories f

Seite 47

to set up many Directory Servers. Many of the parameters can be the same, such as ConfigDirectoryLdapURL, ones specific to the host, such as FullMachi

Seite 48

Table 1.1. set up-ds- admin Opt ionsOption Alternate Options Description Example--silent -s This sets that thesetup script will run insilent mode, dra

Seite 49 - 4.1. Installing the JRE

--logfile name -l This parameterspecifies a log file towhich to write theoutput. If this is not set,then the setupinformation is written toa temporary

Seite 50 - 4.3. Express Setup

Red Hat Directory Server 8.0 Installation Guidefor installation and upgradeEdition 8.0.5Ella Deo n Lackey

Seite 51

NOTEIt is possible to use y and n with the yes and no inputs described in Section 6.3.5, “About .inf FileParameters”.Chapter 1. Preparing for a D irec

Seite 52

Table 1.2. Comparison of Setup TypesSetupScreenParameterInputExpress Typical Custom Silent SetupFileParameterContinue withsetupYes or no N/AAccept lic

Seite 53 - 4.4. Typical Setup

o=NetscapeRootGive theConfigurationDirectoryServer user ID[a]admin[General]ConfigDirectoryAdminID=adminGive theConfigurationDirectoryServer userpasswo

Seite 54 - System Group [daem on]:

=comSet theDirectoryManager IDcn=DirectoryManager[slapd]RootDN=cn=DirectoryManagerSet theDirectoryManagerpasswordpassword[slapd]RootDNPwd=passwordInst

Seite 55

which theAdministrationServer runsRed HatEnterpriseLinux andSolaris) ordaemon (onHP-UX)[admin]SysUser=nobodyAre you readyto configureyour servers?Yes

Seite 56 - 4.5. Custom Setup

Chapter 2. System RequirementsBefore configuring the default Red Hat Directory Server 8.0 instances, it is important to verify that thehost server has

Seite 57

Directory Server is supported on these operating systems: Red Hat Enterprise Linux 4 and 5 (x86 andx86_64), HP-UX 11i (IA 64), and Sun Solaris 9 (spar

Seite 58

NOTEdsktune is run every time the Directory Server configuration script, setup-ds-adm in, is run.2.2.2. Red Hat Enterprise Linux 4 and 5Directory Serv

Seite 59

2.2.2.1. Red Hat Ent erprise Linux Pat chesThe default kernel and glibc versions for Red Hat Enterprise Linux 4 and 5 are the only requiredversions fo

Seite 60 - 5.1. Installing the JRE

3. Then increase the maximum number of open files on the system by editing the /etc/security/lim its.conf configuration file. Add the following entry

Seite 61

Legal Not iceCopyright © 2008 Red Hat, Inc..This document is licensed by Red Hat under the Creative Commons Attribution-ShareAlike 3.0 UnportedLicens

Seite 62

Table 2.4 . HP-UX 11iCriteria RequirementsOperating System HP-UX 11i with the latest patches and upgradesCPU Type HP 9000 architecture with an Itanium

Seite 63 - 5.3. Express Setup

2.2.3.2. HP-UX System Configurat ionBefore setting up Directory Server, tune your HP-UX system so Directory Server can access therespective kernel par

Seite 64

3. Remount the filesystem./usr/sbin/mount -F vxfs -o largefiles /dev/vg01/export2.2.3.2.5. DNS RequirementsIt is very important that DNS and reverse

Seite 65 - 5.4. Typical Setup

Table 2.7. Sun Solaris sparcv9Criteria RequirementsOperating System Solaris 9 with the latest patches and upgradesCPU Type UltraSparc-IIi SPARC v9 300

Seite 66

Table 2.8. Sun Solaris Pat chesPatch ID Description112998-03 SunOS 5.9: patch /usr/sbin/syslogd112875-01 SunOS 5.9: patch /usr/lib/netsvc/rwall/rpc.rw

Seite 67 - Administration port [9830]:

used. T his package contains a 64-bit version of Perl 5.8. It is not possible to use the Perl versioninstalled in /usr/bin/perl on Solaris because it

Seite 68 - 5.5. Custom Setup

2.2.4 .2.4 . File Descript orsFor a large deployment or to support a large number of concurrent connections, increase the number offile descriptors av

Seite 69

Chapter 3. Setting up Red Hat Directory Server on Red HatEnterprise LinuxInstalling and configuring Red Hat Directory Server on Red Hat Enterprise Lin

Seite 70

3.1. Installing the JRENecessary Java JRE libraries are not bundled with Directory Server. T hey must be downloaded andextracted separately before ins

Seite 71

Alternatively, download the latest packages from the Red Hat Directory Server 8.0channel on Red Hat Network, http://rhn.redhat.com.It is also possible

Seite 72

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Seite 73 - *.* .*.*

WARNINGIf Directory Server is already installed on your machine, it is extremely important that you performa migration, not a fresh installation. Migr

Seite 74

NOTETo register the Directory Server instance with an existing Configuration Directory Server,select yes. T his continues with the registration proces

Seite 75 - 6.3. Silent Setup

1. Get the Administration Server port number from the Listen parameter in the console.confconfiguration file.grep \^Listen /etc/dirsrv/admin-serv/con

Seite 76

Computer name [ldap.exam ple.com]:NOTEThe setup program gets the host information from the /etc/resolv.conf file. If thereare aliases in the /etc/host

Seite 77

10. Set the administration domain. T his defaults to the host's domain. For example:Administration Domain [example.com]:11. Enter the Director

Seite 78

/usr/bin/redhat-idm-console -a http://localhost:9830NOTEIf you do not pass the Administration Server port number with the redhat-idm -consolecommand,

Seite 79

NOTEThe setup program gets the host information from the /etc/resolv.conf file. If thereare aliases in the /etc/hosts file, such as ldap.exam ple.com

Seite 80

Administration Domain [redhat.com]:11. Enter the Directory Server port number. T he default is 389, but if that port is in use, the setupprogram supp

Seite 81

Are you ready to set up your servers? [yes]:Creating directory server . . .Your new DS instance 'example3' was successfully created.Creating

Seite 82

Chapter 4. Setting up Red Hat Directory Server on HP-UX 11iInstalling and configuring Red Hat Directory Server on HP-UX has three major steps:1. Inst

Seite 83

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Seite 84

NOTEDirectory Server 8.0 requires JRE version 1.5.0.Download the JRE from http://www.hp.com/products1/unix/java/, and install it according to the HP J

Seite 85

NOTEThe setup program gets the host information from the /etc/resolv.conf file. If there arealiases in the /etc/hosts file, such as ldap.example.com ,

Seite 86

NOTETo register the Directory Server instance with an existing Configuration Directory Server,select yes. T his continues with the registration proces

Seite 87

1. Get the Administration Server port number from the Listen parameter in the console.confconfiguration file.grep \^Listen /etc/dirsrv/admin-serv/con

Seite 88

Computer name [ldap.exam ple.com]:NOTEThe setup program gets the host information from the /etc/resolv.conf file. If thereare aliases in the /etc/host

Seite 89

10. Set the administration domain. T his defaults to the host's domain. For example:Administration Domain [example.com]:11. Enter the Director

Seite 90

/opt/dirsrv/bin/redhat-idm -console -a http://localhost:9830NOTEIf you do not pass the Administration Server port number with the redhat-idm -consolec

Seite 91

NOTEThe setup program gets the host information from the /etc/resolv.conf file. If thereare aliases in the /etc/hosts file, such as ldap.exam ple.com

Seite 92

Administration Domain [redhat.com]:11. Enter the Directory Server port number. T he default is 389, but if that port is in use, the setupprogram supp

Seite 93

Are you ready to set up your servers? [yes]:Creating directory server . . .Your new DS instance 'example3' was successfully created.Creating

Seite 94 - 7.2. LDAP Tool Locations

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Seite 95

Chapter 5. Setting up Red Hat Directory Server on Sun SolarisInstalling and configuring Red Hat Directory Server on Sun Solaris has three major steps:

Seite 96 - 7.7. Troubleshooting

IMPORTANTSolaris requires installing the 32-bit version of the JRE as well as installing the 64-bit version.The 32-bit version is used for the applet

Seite 97

2. Download the Directory Server packages from Red Hat Network. This can be done through a webbrowser by logging into Red Hat Network and selecting t

Seite 98

for i in `ls *.pkg`; do yes all | pkgtrans $i /directory/ ; done4. Add the package:yes yes | pkgadd -d /directory/ allIf another application such as

Seite 99 - 8.1. Migration Overview

1. After the Directory Server packages are installed as described in Section 5.2, “Installing theDirectory Server Packages”, then launch the setup-ds

Seite 100

10. T he last screen asks if you are ready to set up your servers. Select yes.Are you ready to set up your servers? [yes]:Creating directory server .

Seite 101

WARNINGIf Directory Server is already installed on your machine, it is extremely important that you performa migration, not a fresh installation. Migr

Seite 102

not possible to register it with another directory. Select n to set up this Directory Server as aConfiguration Directory Server and move to the next t

Seite 103 - 8.4. Migration Scenarios

17. The last screen asks if you are ready to set up your servers. Select yes.Are you ready to set up your servers? [yes]:Creating directory server .

Seite 104

WARNINGIf Directory Server is already installed on your machine, it is extremely important that you performa migration, not a fresh installation. Migr

Seite 105 - IMPORTANT

Red Hat Directory Server 8.0 Installation Guide4

Seite 106

NOTETo register the Directory Server instance with an existing Configuration Directory Server,select yes. T his continues with the registration proces

Seite 107

silent setup instead, and use the SchemaFile directive in the .inf to specify additional schemafiles. See Section 6.3.5.1, “.inf File Directives” for

Seite 108

NOTEIf you do not pass the Administration Server port number with the redhat-idm -consolecommand, then you are prompted for it at the Console login sc

Seite 109 - Glossary

Chapter 6. Advanced Setup and ConfigurationAfter the default Directory Server and Administration Server have been configured, there are toolsavailable

Seite 110

If there are proxies for the HT T P connections on the client machine running the Directory ServerConsole, the configuration must be changed in one of

Seite 111

adm in.pl except that the questions about the Configuration Directory Server and AdministrationServer are omitted. Using this command to create a Dire

Seite 112

[General] FullMachineName= dir.example.com SuiteSpotUserID= nobody SuiteSpotGroup= nobody AdminDomain= example.com ConfigDirectoryAdminID= admin Confi

Seite 113

NOTEWhen creating a single instance of Directory Server, the Directory Server packages must alreadybe installed, and the Administration Server must al

Seite 114

For example, to set the machine name, suffix, and Directory Server port of the new instance, thecommand is as follows:/usr/sbin/setup-ds-admin.pl Gene

Seite 115

Table 6.1. set up-ds- admin Opt ionsOption Alternate Options Description Example--silent -s This sets that thesetup script will run insilent mode, dra

Seite 116

PrefaceThis installation guide describes the Red Hat Directory Server 8.0 installation process and the migrationprocess. T his manual provides detaile

Seite 117

specifies a log file towhich to write theoutput. If this is not set,then the setupinformation is written toa temporary file./export/example2007.logFor

Seite 118

adm in.pl command.NOTEProviding configuration parameters with the setup-ds-adm in.pl command is described inSection 1.3, “About the setup-ds-admin.pl

Seite 119

Table 6.2. [General] DirectivesDirective Description Required ExampleFullMachineName Specifies the fullyqualified domain nameof the machine onwhich yo

Seite 120

configuration directory.This is usually admin.ConfigDirectoryAdminPwdSpecifies the passwordfor the admin user.YesRed Hat Directory Server 8.0 Installa

Seite 121

Table 6.3. [slapd] DirectivesDirective Description Required ExampleServerPort Specifies the port theserver will use for LDAPconnections. Forinformatio

Seite 122

directive has no effect.The default is no.AddSampleEntries Sets whether to load anLDIF file with entries forthe user directoryduring configuration.The

Seite 123

used, then the defaultis 0, meaning theconfiguration data arestored in the newinstance.Chapter 6. Advanced Setup and Configuration 83

Seite 124

Table 6.4 . [admin] DirectivesDirective Description Required ExampleSysUser Specifies the user aswhich theAdministration Serverwill run. T he default

Seite 125

Example 6.1. .inf File for a Custom Installation[General]FullMachineName= ldap.example.comSuiteSpotUserID= nobodySuiteSpotGroup=

Seite 126

Example 6.2. .inf File for Registering the Instance with a Configuration Directory Server(Typical Setup)[General] FullMachineName= dir.example.com Sui

Seite 127

Example 1. Example CommandTo start the Red Hat Directory Server:service dirsv startAll of the tools for Red Hat Directory Server are located in the /u

Seite 128

/usr/sbin/ds_removal -s example1 -w itsasecret/usr/sbin/ds_removal -s example2 -w itsasecret/usr/sbin/ds_removal -s example3 -w itsasecret2. Stop the

Seite 129

2. Stop the Administration Server./etc/init.d/dirsrv-admin stop3. Then use the system tools to remove the packages. For example:#!/bin/bash for i i

Seite 130

Chapter 7. General Usage InformationThis chapter contains common information that you will use after installing Red Hat Directory Server 8.0,such as w

Seite 131

Table 7.2. Red Hat Enterprise Linux 4 and 5 (x86_64 )File or Direct ory Locat ionLog files /var/log/dirsrv/slapd-instanceConfiguration files /etc/dir

Seite 132

Table 7.4 . HP-UX 11i (IA64 )File or Direct ory Locat ionLog files /var/opt/log/dirsrv/slapd-instanceConfiguration files /etc/opt/dirsrv/slapd-instanc

Seite 133

subsequent logins, the URL is saved. If you do not pass the Administration Server port number with the redhat-idm -console command, then you are promp

Seite 134

service dirsrv-adm in {start|stop|restart}On Solaris, the service is init.d:/etc/init.d/dirsrv-admin {start|stop|restart}7.6. Resetting the Directory

Seite 135

After the setup, the dsktune utility can determine the Directory Server patch levels and kernelparameter settings. T o launch dsktune, Directory Serve

Seite 136

7.7.2.2. Problem: The port is in useWhen setting up a Directory Server instance, you receive an error that the port is in use. This is verycommon whe

Seite 137 - - Solaris, Solaris

Chapter 8. Migrating from Previous VersionsRed Hat Directory Server 6.x and 7.x instances can be migrated to Directory Server 8.0. Migration carriesov

Kommentare zu diesen Handbüchern

Keine Kommentare