
NMAS Considerations
605
n
ov
do
cx (e
n)
11
Ju
ly 20
08
NOTE:
Depending on how the product was used, the objects and items referred to might or might
not be present. If the objects and items referred to are not present in the source tree, you can skip the
step.
1
Delete the W0 object and the KAP container in the source tree.
The KAP container is in the Security container. The W0 object is in the KAP container.
2
On all servers in the source tree, delete the Security Domain Infrastructure (SDI) keys by
deleting the
sys:\system\nici\nicisdi.key
file.
IMPORTANT:
Make sure that you delete this file on
all
servers in the source tree.
Other Security-Specific Operations
If a Security container exists in the source tree, delete the Security container before you merge the
trees.
A.2.2 Performing the Tree Merge
eDirectory trees are merged using the ndsmerge utility. For more information, see
Chapter 9,
“Merging Novell eDirectory Trees,” on page 223
and
Appendix B, “Novell eDirectory Linux and
UNIX Commands and Usage,” on page 607
.
A.2.3 Product-Specific Operations to Perform after the Tree
Merge
This section contains the following information:
“Novell Security Domain Infrastructure” on page 605
“Novell Certificate Server” on page 606
“Novell Single Sign-On” on page 606
“NMAS” on page 606
Novell Security Domain Infrastructure
If the W0 object existed in the target tree before the merge, the Security Domain Infrastructure (SDI)
keys used by the servers that formerly resided in the target tree must be installed in the servers that
formerly resided in the source tree.
The easiest way to accomplish this is to install Novell Certificate Server 2.52 or later on all servers
formerly in the source tree that held SDI keys (the
sys:\system\nici\nicisdi.key
file).
This should be done even if the Novell Certificate Server has already been installed on the server.
If the W0 object did not exist in the target tree before the merge but did exist in the source tree, the
SDI must be reinstalled in the resulting tree.
The easiest way to accomplish this is to install Novell Certificate Server 2.52 or later on the servers
in the resulting tree. Novell Certificate Server must be installed on the servers formerly in the source
tree that held SDI keys (the
sys:\system\nici\nicisdi.key
file). It can also be installed
on other servers in the resulting tree.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...