Domain Services for Windows on OES11SP1

50
Deploying Domain Services for Windows Bas Penris, Etty Hillesum Lyceum [email protected]

Transcript of Domain Services for Windows on OES11SP1

Page 1: Domain Services for Windows on OES11SP1

Deploying Domain Services for WindowsBas Penris, Etty Hillesum Lyceum

[email protected]

Page 2: Domain Services for Windows on OES11SP1

Introduction to DSfW

• DSfW is a set of tech that allows OES to present itself as AD

• Setup non name mapped to get familiar with the technology

• Use IDM to provision users and groups

• AD trusts

• No MS-licensing

• Complicated piece of technology, a lot can go wrong

• That’s why Non-Name Mapped is a good idea

Page 3: Domain Services for Windows on OES11SP1

Benefits

• AD applications integrate very easily

• eDir still outperforms AD by a couple of factors

• eDir style management, got to hate MMC

• Most of it is technology known to you

Page 4: Domain Services for Windows on OES11SP1

Downside

• Troubleshooting can be hard

• MS points at Novell/NetIQ and vice versa

• xadcntl restart usually fixes things

• Non Name Mapped doesn’t break as much

Page 5: Domain Services for Windows on OES11SP1

Key components

• eDirectory!

• Kerberos Key Distribution Center

• NMAS extentions to update AD-credentials when UP is changed

• AD Provisioning Handler/DS Agent: AD security & information model, makes sure users and groups have SIDs

• Domain Services Daemon: Windows RPCs, LSA, SAM & NetLogon

• NAD Virt. Layer: Virtualises AD Inf. Mod. for LDAP

• CIFS/DDNS/NTP

Page 6: Domain Services for Windows on OES11SP1

Preparing

• Choose a domain name

• .local is not supported but it does work, see support.novell.com forinfo on how to configure DNS

• dsfw.yourdomain.tld or ad.yourdomain.tld or blah.yourdomain.tld

• Create glue records in your current DNS infrastructure

• Do it multiple times to get the hang of the technology

• Update

• Static IP

• /etc/resolv.conf points to 127.0.0.1

Page 7: Domain Services for Windows on OES11SP1

Make it easy!

• Use a VM, either in ESXi, Workstation, VirtualBox or Hyper-V

• OES11SP2

• Use pvscsi and vmxnet3 for performance

Page 8: Domain Services for Windows on OES11SP1

Installation

• Just select the DSfW pattern

• I always install iManager as well

• Let’s walk through the installation

Page 9: Domain Services for Windows on OES11SP1
Page 10: Domain Services for Windows on OES11SP1
Page 11: Domain Services for Windows on OES11SP1
Page 12: Domain Services for Windows on OES11SP1
Page 13: Domain Services for Windows on OES11SP1
Page 14: Domain Services for Windows on OES11SP1
Page 15: Domain Services for Windows on OES11SP1
Page 16: Domain Services for Windows on OES11SP1
Page 17: Domain Services for Windows on OES11SP1
Page 18: Domain Services for Windows on OES11SP1
Page 19: Domain Services for Windows on OES11SP1
Page 20: Domain Services for Windows on OES11SP1
Page 21: Domain Services for Windows on OES11SP1
Page 22: Domain Services for Windows on OES11SP1
Page 23: Domain Services for Windows on OES11SP1

Not done yet!

Page 24: Domain Services for Windows on OES11SP1

DSfW Server Authentication

Page 25: Domain Services for Windows on OES11SP1
Page 26: Domain Services for Windows on OES11SP1
Page 27: Domain Services for Windows on OES11SP1
Page 28: Domain Services for Windows on OES11SP1
Page 29: Domain Services for Windows on OES11SP1
Page 30: Domain Services for Windows on OES11SP1
Page 31: Domain Services for Windows on OES11SP1
Page 32: Domain Services for Windows on OES11SP1
Page 33: Domain Services for Windows on OES11SP1
Page 34: Domain Services for Windows on OES11SP1
Page 35: Domain Services for Windows on OES11SP1
Page 36: Domain Services for Windows on OES11SP1
Page 37: Domain Services for Windows on OES11SP1
Page 38: Domain Services for Windows on OES11SP1
Page 39: Domain Services for Windows on OES11SP1

Crontab

Page 40: Domain Services for Windows on OES11SP1
Page 41: Domain Services for Windows on OES11SP1

Windows XP

Page 42: Domain Services for Windows on OES11SP1

Add to domain

Page 43: Domain Services for Windows on OES11SP1

Authenticate

Page 44: Domain Services for Windows on OES11SP1

Success!

Page 45: Domain Services for Windows on OES11SP1
Page 46: Domain Services for Windows on OES11SP1

Log in

Page 47: Domain Services for Windows on OES11SP1

Logged in!

Page 48: Domain Services for Windows on OES11SP1

What’s next?

• Connect AD-enabled applications

• Fill your AD with users

• Use MMC or iManager to manage users

• Wait for OES-Next to get your NSS filesystems in there ;)

Page 49: Domain Services for Windows on OES11SP1

Support

• www.dsfwdude.com

• Helpful Install TIDs: https://www.novell.com/support/kb/doc.php?id=7000068

• General TIDs: https://www.novell.com/support/kb/doc.php?id=7002366

• Verify install: https://www.novell.com/support/kb/doc.php?id=7001884

• Basic Troubleshooting: https://www.novell.com/support/kb/doc.php?id=3576510

Page 50: Domain Services for Windows on OES11SP1

Thank you!