background image

14

Novell iManager 2.7 Installation Guide

n

ov

do

cx (e

n)

  16
 Ap
ril 20

10

1.3.2  Windows

The following instructions show how to create a keypair in eDirectory and export the Public, Private 
and Root Certificate Authority (CA) keys via a PKCS#12 file on the Windows platform. This 
includes modifying Tomcat's 

server.xml

 configuration file in order to use the PKCS12 directive 

and point the configuration to an actual P12 file rather than use the default JKS keystore.

The files, and their default locations, associated with this process are as follows:

Š

The temporary keypair: 

C:\Program Files\Novell\Tomcat\conf\ssl\. keystore

.

Š

The trusted root certificates: 

C:\Program Files\Novell\jre\lib\security\cacerts

.

Š

Configure Tomcat's certificate use:

 C:\Program Files\Novell\Tomcat\conf\server.xml

1. Create a new server certificate with iManager.

In iManager, select Novell Certificate Server > Create Server Certificate. Select the appropriate 
server, specify a nickname and accept the rest of the certificate defaults.

2. Export the server certificate.

In iManager, select Directory Administration > Modify Object. Browse to and select the KMO 
object. In the Certificates tab, select Export. Specify a password and save the server certificate 
as a pkcs12 file (

.pfx

).

3. Convert the 

.pfx

 file to a 

.pem

 file.

NOTE: 

Openssl is not installed on Windows by default, but a version for the Windows 

platform is available on the 

Openssl Web site (http://www.openssl.org/related/binaries.html)

Alternatively, you can convert the certificate on a Linux platform, on which Openssl is installed 
by default.

To do this, use a command similar to the following:

openssl pkcs12 -in newtomcert.pfx -out newtomcert.pem

Specify the certificate password from step 2, and specify a password for the new 

.pem

 file. You 

can use the same password, if desired.

4. Convert the 

.pem

 file to a 

.p12

 file.

To do this, use a command similar to the following:

openssl pkcs12 -export -in newtomcert.pem -out newtomcert.p12 -name "New 
Tomcat"

Specify the certificate password from step 3, and specify a password for the new 

.p12

 file. You 

can use the same password, if desired.

5. Copy the .p12 file to the Tomcat certifcate location.

By default, this is 

C:\Program Files\Novell\Tomcat\conf\ssl\

.

6. Stop the Tomcat Service.

/etc/init.d/novell-tomcat5 stop

7. Edit the Tomcat’s 

server.xml

 and add 

keystoreType

keystoreFile

, and 

keystorePass

 

variables to let Tomcat use the newly created 

.p12

 certificate file. For example:

Summary of Contents for IMANAGER - INSTALLATION V2.7

Page 1: ...Novell www novell com novdocx en 16 April 2010 AUTHORIZED DOCUMENTATION Novell iManager 2 7 Installation Guide iManager 2 7 October 15 2010 Installation Guide...

Page 2: ...and the trade laws of other countries You agree to comply with all export control regulations and to obtain any required licenses or classification to export re export or import deliverables You agre...

Page 3: ...Trademarks For Novell trademarks see the Novell Trademark and Service Mark list http www novell com company legal trademarks tmlist html Third Party Materials All third party trademarks are the prope...

Page 4: ...4 Novell iManager 2 7 Installation Guide novdocx en 16 April 2010...

Page 5: ...iManager Workstation on Windows Clients 23 1 6 Silent Installation of iManager Server 24 1 6 1 Standard Silent Install 24 1 6 2 Customized Silent Install 24 2 Upgrading iManager 27 2 1 Upgrade Scenar...

Page 6: ...6 Novell iManager 2 7 Installation Guide novdocx en 16 April 2010...

Page 7: ...e documentation or go to www novell com documentation feedback html and enter your comments there Documentation Updates For the most current version of the iManager 2 7 Installation Guide see the Engl...

Page 8: ...8 Novell iManager 2 7 Installation Guide novdocx en 16 April 2010...

Page 9: ...er called iManager Workstation is installed on a client workstation rather than a server Use the following guidelines to decide which version fits best in your environment or whether your eDirectory m...

Page 10: ...t Windows Server 2008 R2 Enterprise Edition 64 bit Windows Server 2008 R2 Standard Edition 64 bit NOTE iManager 2 7 does not include Solaris as a supported platform However iManager can still manage a...

Page 11: ...iManager 2 7 the term Mobile iManager has been changed to iManager Workstation iManager workstation bundles the following versions of Tomcat and Java Tomcat 5 5 29 Java 1 6 0_20 1 1 3 Backward Compat...

Page 12: ...on date of one year This is not intended to be a long term implementation It is a temporary solution to get your system up and running so you can securely use iManager immediately following installati...

Page 13: ...n newtomcert pem out newtomcert p12 name New Tomcat Specify the certificate password specified in step 3 and specify a password for the new p12 file You can use the same password if desired 5 Stop Tom...

Page 14: ...he KMO object In the Certificates tab select Export Specify a password and save the server certificate as a pkcs12 file pfx 3 Convert the pfx file to a pem file NOTE Openssl is not installed on Window...

Page 15: ...n Guide for information on customizing iManager s plug in download and install process For a clean install the typical plug ins are preselected For an upgrade only plug ins that need to be updated are...

Page 16: ...64 bit NOTE If you are using PKI plug in you must install the following RPMs on the iManager server SLES 10 32 bit compat compat 2006 1 25 11 2 SLES 10 64 bit compat 32bit compat 32bit 2006 1 25 11 2...

Page 17: ...u can specify either of the following components Novell iManager 2 7 Tomcat JVM Installs all the three components Novell iManager 2 7 Installs only the iManager component You can specify this if you a...

Page 18: ...horized user post install from the Configure iManager Server Configure iManager Security page in iManager For more information see Authorized Users and Groups in the iManager 2 7 4 Administration Guid...

Page 19: ...ng Web server infrastructure if desired Processor Pentium III 600 MHz or higher processor Disk Space 500 MB minimum for a local installation Memory 512 MB of RAM 1024 MB recommended iManager can insta...

Page 20: ...e appears in the plug in download area one or more of the following conditions exist There are no updated plug ins available on the Novell download site There is a problem with your Internet connectio...

Page 21: ...it is being used by another process 15 Click Done to quit the installer A browser window appears which displays the Getting Started page Wait for iManager to initialize before attempting access To acc...

Page 22: ...vell com search for iManager products select iManager 2 7 then download iMan_27_workstation_linux tar bz2 to a directory on your server 2 Extract the file using the following command tar xjvf iMan_27_...

Page 23: ...200 MB minimum Memory 256 MB of RAM 512 MB recommended Do not run iManager Workstation from a path with spaces in it If you are running a Novell Client earlier than version 4 91 make sure that the NMA...

Page 24: ...silent or enter the following for Windows iManagerInstall exe i silent 1 6 2 Customized Silent Install To perform a customized silent install for more control over which modules are installed 1 Create...

Page 25: ...ault path where iManager is to be installed 4 To specify particular modules to download use the following examples providing the module ID and version from the MANIFEST MF file located in the NPM s ME...

Page 26: ...26 Novell iManager 2 7 Installation Guide novdocx en 16 April 2010...

Page 27: ...ger 2 7 on a standalone server 2 1 2 Upgrade Scenario for Windows Running iManager 2 7 with Tomcat 5 0 The upgrade scenario for Windows is about installing new iManager 2 7 that runs Tomcat 5 5 28 on...

Page 28: ...inst_oes_lx data front html front When you upgrade OES to OES 2 SP1 iManager will be upgraded to iManager 2 7 2 iManager 2 7 Support Pack 2 2 1 5 Upgrade Scenario for Upgrading iManager 2 7 to the Lat...

Page 29: ...lly installed you might see discrepancies in the module report for any given collection from the Role Based Services RBS Configuration page In order for the numbers to match between iManager installat...

Page 30: ...6 April 2010 2 Select the plug in you want to re install or migrate then click Edit You can only edit one plug in at a time 3 Click Install You should receive a message saying it was successful Do thi...

Page 31: ...stall because it did not install them Likewise if you have created new files or modified existing files within the directory structure that was originally laid down during the install these files are...

Page 32: ...d on the same server as iManager NICI is required to continue to run eDirectory When you remove iManager 2 7 only some files in the file system are removed You are asked if you want to remove all iMan...

Reviews: