Release Notes for iPlanet Console and Administration Server

Version 5.0

Updated March 5, 2001




Release Notes for iPlanet Console and Administration Server Version 5.01 are available at: http://docs.iplanet.com/docs/manuals/console/50/501_notes.htm

These release notes contain important information available at the time of the version 5.0 release of iPlanet Console and Administration Server. New features and enhancements, installation notes, known problems, and other late-breaking issues are addressed here. Parenthetical numbers contained within, or following the topics, are tracking numbers. Tracking numbers are useful when discussing issues with Technical Support or Professional Services.

Read this document before you begin using iPlanet Console and Administration Server.

An electronic version of these release notes can be found at the iPlanet documentation web site: http://docs.iplanet.com/docs/manuals/console.htm. Check the web site prior to installing and setting up your software and then periodically thereafter to view the most up-to-date release notes and manuals.

iPlanet Console incorporates compression code by the Info-ZIP group. There are no extra charges or costs due to the use of this code, and the original compression sources are freely available from ftp://ftp.freesoftware.com/ on the Internet.

These release notes contain the following sections:





What's New in iPlanet Console and Administration Server, Version 5.0

iPlanet Console and Administration Server 5.0 let you manage iPlanet software and users in your enterprise. iPlanet Console provides a unified administration interface for servers and applications as well as to user and group entries in an instance of Directory Server. iPlanet Administration Server carries out operation requests from servers and applications. Version 5.0 of iPlanet Console and Administration Server includes a redesigned Access Control Editor and a new security management framework.





Installation Issues

Complete installation instructions and release notes for Netscape and iPlanet servers are available online at this location: http://docs.iplanet.com.

Installing and Upgrading iPlanet Console


HP-UX

You cannot install a simplified Chinese version of iPlanet Administration Server 5.0 if your configuration directory is stored on a machine that is not running HP-UX. To install Administration Server that will use a simplified Chinese version, the instance of Directory Server containing your configuration directory must be running on HP-UX, either locally or on a remote machine (401888).


HP-UX for 64-bit architectures

Do not attempt to install iPlanet Console using a double byte Administration domain name. The iPlanet Server Setup program will not work as designed (355492). Installing patch PHSS_15840 will solve this problem. Contact Hewlett-Packard for detailed information on obtaining this patch.


Silent Install Cache

You can save the installation cache when you install iPlanet Console. All the values you specify during installation are saved to a file when you save the installation cache. This file is useful when you want to perform subsequent silent installations. To save the installation cache, navigate to the server root, and then enter setup -k at the command line (339769). For more information on silent installation, see your server's documentation (available at http://docs.iplanet.com).


NFS

If you are running the iPlanet Server Products Setup program to install Administration Server and Console binary files that are mounted using NFS, keep the following in mind:


Default User Directory over SSL

If the default user directory for your administration domain is stored on an instance of Directory Server that is running SSL, you will not be able to install or upgrade iPlanet Administration Server (395410). To work around this problem, follow the appropriate set of instructions:


To Install a New Instance of Administration Server for a Directory Server Using SSL

  1. In the navigation tree, select the administration domain that is communicating with SSL to Directory Server.

  2. In the right-hand panel, click Edit.

  3. Change the value for "User directory host and port" to the non-SSL port.

  4. Install iPlanet Administration Server 5.0.

  5. Start Console and log into iPlanet Administration Server.

  6. Change the value for "User directory host and port" back to the SSL port.

  7. Decide how you want to connect to the user directory and configure Administration Server accordingly:

    • If you want to connect to the user directory using encryption, run Administration Server's Certificate Installation Wizard to create a key and certificate database and to install a trusted CA certificate.

    • If you do not want to connect to the user directory using encryption, configure Administration Server to use the non-SSL Directory Server port. For more information, see "To Change User Directory Settings for a Server Group" in chapter 7 of the Managing Servers with iPlanet Console .


To Upgrade an Existing Instance of Administration Server for a Directory Server Using SSL
  1. Configure the existing instance of Administration Server to communicate with a non-SSL Directory Server:

    • If the existing instance is communicating with a SSL Directory Server port, but the default Directory Server port for your administration domain is non-SSL, configure the instance of Administration Server to use the default port. To do this, open the server management window for the instance of Administration Server, click the Configuration tab, and then click the User DS tab. Select Use Default User Directory and then click Save.

    • If the existing instance is configured to communicate with the default Directory Server port, and the default port is SSL, configure the administration domain to use a non-SSL Directory Server port as its default. To do this: select the administration domain in the navigation tree, click Edit in the right-hand panel, and then change the value for "User directory host and port" to the non-SSL port.

  2. Perform the upgrade by installing iPlanet Administration Server 5.0 into your existing server root folder.

  3. Start Console and log in to Administration Server.

  4. If you want to connect to a user directory using encryption, configure either the administration domain or the upgraded instance of Administration Server to connect to the SSL port. To do this, follow the procedures outlined in step 1, substituting the SSL port for the non-SSL one.


Double Byte Domain Name

During Console installation, the setup utility retrieves the domain name from Directory server. If the domain name is a double byte value (eg. Chinese or Japanese character set) it is displayed incorrectly. The correct double byte domain name must be added manually. (521506)


Using Netscape Directory Server 4.0 or Earlier

If your configuration directory is running on Netscape Directory Server 4.0 or earlier, you may receive an "error 14" message when performing Console operations (392925). This is because Console 4.1 and higher require schema updates to the directory. To fix this problem, install the latest version of iPlanet Directory Server.


Using Escape Characters During Installation

Do not use escape characters in domain names during iPlanet Console installation. Using a traditional escaped character (such as \,) when specifying a domain name during installation will cause the iPlanet Server Products Setup program to fail (420089). If you want to use escape characters in your domain names, you may use Console to add them after Console is installed and the domain is created.





Known Problems and Limitations

This section describes the following known problems and related solutions. Parenthetical numbers contained within, or following the topic, are tracking numbers. Tracking numbers are useful when discussing issues with Technical Support or Professional Services:


Security Issue: Windows NT Allowed IP Addresses

In the Windows NT environment, the default setup allows connections to the Administration Server from any host. If this presents a security concern in your environment, you can use the Administation Server Console to make the access more restrictive. For complete instructions on server access restriction see Managing Servers with iPlanet Console chapter 7 Administration Server Configuration (521519).


Starting iPlanet Console

AIX. You cannot run iPlanet Console on the remote display of some Solaris releases (394393).

HP-UX. If you want to run iPlanet Console on a non-HP remote display, you must set the LANG environment variable to c.iso88591


Loss of Network Connection

If you lose a network connection while iPlanet Console is running, iPlanet Console may become inoperable. Re-establish your network connection, then restart iPlanet Console (106714).


Login Window is Hidden

When starting iPlanet Console using some window managers (Enlightenment, WindowMaker, or Gnome), the Login window may be hidden behind the iPlanet Console splash screen, and you will not be able to log in (345545). As a workaround, start iPlanet Console at the command line by entering startconsole -x nologo.


Inputting Asian Characters on HP-UX

If you are entering text into iPlanet Console, Asian characters (Japanese, Chinese, or Korean) may appear as empty boxes (393006). To fix this problem, install the required TrueType fonts for the language you need on your system, and then set the JAVA_FONTS environment variable to the location of these fonts.

You may also want to contact Hewllet Packard about an updated Java Runtime Environment (JRE).

When inputting Asian characters, the Input Method Editor (IME) may fail to work properly (401880). To fix this problem, install the following patches (available from the HP web site):



Patch Name

Version

Description

B8725AA

A.01.01

CIFS/9000 Server Lic. for 9000Servers

HPUXEng64RT

B.11.00

English HP-UX 64-bit RuntimeEnvironment

HPUXSCh64RT

B.11.00.01

Simplified Chinese HP-UX64-bit Runtime Environment

HPUXTCh64RT

B.11.00.01

Traditional Chinese HP-UX 64-bit Runtime Environment

UXCoreMedia-S

B.11.00.01

HP-UX Simplified Chinese Media Kit (Reference Only. See Description)

UXCoreMedia-T

B.11.00.01

HP-UX Traditional Chinese Media Kit (Reference Only. See Description)

XSWECO223

A.1.0

Patch Replacement bundle

XSWGR1100

B.11.00.48

HP-UX General Release Patches March 2000

XSWHWCR1100

B.11.00.48

HP-UX Hardware Enablement and Critical Patches March 2000

PHCO_20765

1.0

libc cumulative patch

PHSS_15396

1.0

Asian Printer cumulative patch

PHSS_20147

1.0

Asian Input Method cumulative patch

PHSS_20148

1.0

ASX release notes cumulative patch

PHSS_20863

1.0

CDE Msg Cat MAR2000 Periodic Patch

PHSS_21283

1.0

X/Motif 64bit Runtime APR2000 Periodic Patch




Asian Characters in Search Results

When iPlanet Console returns user and group search results, Asian characters (Japanese, Chinese, or Korean) may appear as empty boxes (401889). To fix this problem, change your font settings. To do this:

  1. Select Preferences from the Edit menu option.

  2. Click the Fonts tab.

  3. Make sure that an available Asian font is assigned to each screen element. To see which fonts are available on your system, select a screen element, and then click the Change Font button.

  4. Click OK to save your font settings.

  5. Restart iPlanet Console.

    Your font choices are preserved as part of your Console user preferences.

    For more information on changing Console fonts, see Chapter 3 of the iPlanet Console Server Management Guide (available online at http://docs.iplanet.com/docs/manuals/console.html).


Administration Server Not Locating Directory Server

If you are running Windows NT, Netscape Directory Server may start up after iPlanet Administration Server. If this happens, Administration Server will not be able to retrieve configuration information from the directory. To solve the problem, restart iPlanet Administration Server from the Windows NT Services Control Panel (394281).


Distorted Fonts in Unix

If you are running iPlanet Console on a remote Unix server, fonts may look awkward, resulting in clipped UI text. To fix this problem, adjust font settings through the Preferences dialog box under the Edit menu in Console (336626).


Problems With Help

If clicking a Help button does not open your web browser, displaying help, try opening a browser window before clicking a Help button (399626) (524985).


Proxied Administration Not Supported

iPlanet Console 5.0 does not support proxied administration.


Server Instance Names

Do not use a period (.) in server instance names. If you use a period in a server instance name, iPlanet Console will not recognize the server instance.

For example, the server instance msg.siroe.com is not acceptable; msg-siroe-com is acceptable (311490).


Non-Default User ID

When the default language requires a user ID in a form other than the default (the user's first initial followed by the user's last name), you must manually override the nsuserformat attribute in the configuration directory (117507). To manually override the nsuseridformat attribute:

  1. In iPlanet Console, open the management window for the instance of Directory Server containing the configuration directory you want to modify.

  2. Click the Directory tab.

  3. Expand the navigation tree to follow this path: NetscapeRoot/administrationDomain /Global Preferences.

  4. In the navigation tree, select Global Preferences.

  5. In the right pane double-click Common.

  6. In the Property Editor window, locate the attribute nsuseridformat and enter one of the following values as appropriate:

  7. firstletter_lastname (this is the default value)

    • givenname_firstletter

    • lastname_givenname

    • givenname_lastname

  8. Click OK.

  9. Restart iPlanet Console.


8-bit Characters in User Data

When creating a new user or editing a user's personal data, do not use 8-bit characters in the First Name and Last Name fields. If you use 8-bit characters in the First Name or Last Name fields, the user ID is not automatically generated for you. Instead, use ASCII characters to enter the user's personal data (117507).


Using HP-UX


Improving Administration Express Performance

If the host computer for a server registered in the configuration directory is experiencing network problems, there could be a long delay when the Administration Express page tries to contact the server and create a status page (355354). To improve Administration Express performance, do the following:

  1. Open the adm.conf file located in the server root, </server_root> /admin-serv/config/adm.conf,

  2. Add the following entry: ExpressCGITimeout: x

    In this entry, x is an integer representing how long (in seconds) Administration Express should continue trying to reach the remote server before timing out.


Enabling SSL on Directory Server 4.x Using Console 5.0

After installing iPlanet Console and Administration Server 5.0, if you enable SSL on Netscape Directory Server 4.x, the directory server won't start. You will see the following message in the error log:

"Failed to set SSL cipher preference information: unknown cipher tls_rsa_export1024_with_rc4_56_sha!"

This message is generated because Console 5.0 includes two additional cipher suites that Directory Server 4.x does not recognize.

To work around this problem, do the following with encryption enabled and the directory not running:

Edit the dse.ldif file located in </server_root> /slapd-serverName/config/ as follows:

  1. Remove the two "-tls_" strings from the dse.ldif file. These strings exist under the attribute name "nsssl3ciphers," which is found in the "cn=encryption, cn=config" node beneath the affected server instance SIE.

  2. Start Directory Server from the command-line with start-slapd.

Once you have modified dse.ldif, you can disable and enable encryption for Directory Server by manually modifying the "security on/off" setting in slapd.conf. If you use Console to change your encryption settings or disable and then re-enable encryption, you will have to edit dse.ldif again.


Installing a Fortezza PKCS #11 Module on Windows NT

If the Fortezza PKCS #11 module you want to install is a Dynamic Link Library file (or shared library) and not a JAR file, do not use the "Configure Security Modules" dialog box in iPlanet Console. If you use iPlanet Console's graphical interface, you will not be able to activate Fortezza ciphers. Instead, use the modutil command line utility located at </server_root> /shared/bin/modutil.

To install a Fortezza PKCS #11 Module DLL File:

  1. Locate the server instance for which you want to install the PKCS #11 module.

  2. Open a terminal window.

  3. Go to the Administration Server's configuration directory located at </server_root> /admin-serv/config.

  4. At the prompt, enter this command: </server_root> /shared/bin/modutil -dbdir . -create

  5. This creates the required security module database file (secmod.db) in the Administration Server's configuration directory.

  6. At the prompt, enter this command:

    </server_root> /shared/bin/modutil -dbdir . -add moduleName -libfile libraryFile -nocertdb

    • moduleName is where you specify the name of the PKCS #11 module (you specified this in Step1 when you installed the drivers)

    • libraryFile is where you specify the path to the DLL or other library file containing the implementation of the PKCS #11 interface module.

For example, if you are installing a Litronic token, you would enter: </server_root> /shared/bin/modutil -dbdir . -add CryptOS -libfile core32

For detailed information about modutil, see the iPlanet Console Server Management Guide.


Automatically Starting an SSL-Enabled Instance of Administration Server

To start an SSL-enabled instance of Administration Server without manually entering a password, do the following:

  1. Under /admin-serv/config, create a text file called password.conf. The text file will contain your security device passwords.

  2. Add lines to this file using the following format:

    <token name 1>:<password 1>

    <token name 2>:<password 2>

    .

    .

    <token name x>:<password x>

  3. Substitute the actual name of the token for <token name> and the password associated with the token for <password> . If you have selected multiple tokens in the Administration Server Encryption screen, add all the corresponding token names and passwords on additional new lines.

  4. Most frequently you will use only internal software tokens. In this case the password.conf file must contain only the following:

    Communicator Certificate DB:<password>

    Substitute the password you selected when creating the key and certificate database files in the certificate setup wizard for <password> . (505061) (485321)


Using Green Threads With an Encrypted Instance of Administration Server

If the instance of Administration Server that you want to log in to is running SSL, you cannot use the -g option to start Console using green threads (400746).


Changing Configuration Directory Server Information

If you want to change the port number of the Configuration Directory Server used by your Administration Server, you can use either the following GUI or CLI instructions (391575)(391363):

GUI Instrutions:

  1. Open the Directory Console and select the Configuration tab.

  2. Change the LDAP port to a new value

  3. Click OK. The success dialog tells you to restart the server for the changes to take effect. Do not quit Console.

  4. Restart Directory Server from the command line.

Next, change the Administration Server LDAP port with the following steps:

  1. In Console, select the administration server that you want to change, and then click Open.

  2. Click the Configuration tab, click Settings, and then change the value for Port.

  3. Click OK. The success dialog tells you to restart the server for the changes to take effect.

  4. Quit Console.

  5. Restart Administration Server

To change the Administration Server LDAP port from the command, use the following instructions:

Comand Line Instructions:

  1. Go to the Administration Server's server root and make the following changes:

    Open /admin-serv/config/adm.conf and change LDAP port to the new Configuration Directory Server port number.

    Open /shared/config/dbswitch.conf and change the directory default URL to reflect the new port number.

  2. Restart Administration Server. When you launch Console, it will point to the new Configuration Directory Server port.

  3. Note: The above steps are performed for each individual Administration Server in the topology that will use a new Configuration Directory Server.

These two procedures do not change the default URL for users and groups. To change the User Directory host name or port number for a domain, do the following:

  1. Open iPlanet Console

  2. In the navigation tree, select the administration domain that uses the new or changed Directory Server.

  3. In the right-hand panel, click the Edit button.

  4. In the "User Directory Host and Port" field, enter the new or changed Directory Server host name and port number.

  5. Click OK.

All server instances in the administration domain will now use the new host name and port by default. If you want the instances in a particular server group to use a different User Directory Server, change the User DS settings for the server group's Administration Server.


Server Class Instantiate Error

Terminating the Console Java application while the class download for a server is in progress may

may leave the server class files in an inconsistent state. In this event, future attempts to access the particular server instance fail producing the error message: Server Class Instantiate Error. The following steps are needed to eliminate the error: (518823)

  1. Create a temporary directory. For example: <server_root> /java/jar/<save>

  2. Move all files from your existing <server_root> /java/jar to the new temporary directory

  3. Run the Console and download the server class files again by clicking on the particular server in the topology.

  4. When the class download is sucessful, again move all the files from your existing <server_root> /java/jar to the new temporary directory.

  5. Then, move the contents of temporary directory into <server_root> /java/jar and remove the temporary directory.


Misplaced Console Login Window

If the login window for iPlanet Console appears in the top corner of the screen, making the fields inaccessible, right click the border of the login window and select Move from the menu that appears. Drag the login window to the desired location. If this is not possible, then remove the file $HOME/.mcc/Console.4.0.Login.preferences (521500).


Internet Explorer Client Authentication

Initial setup of the iPlanet Console and Administration Server client authentication feature requires the use of Netscape Communicator to create the key3.db and cert7.db files needed for authentication. (522151)


Certificate Generation

You must type more than one character in each field of the Certificate Request form in the Certificate Set Up Wizard. If a certificate is installed that does not conform to this instruction when generated, iPlanet Console and Administration Server will display the error message: InvalidNicknameException. (520956)


Viewing Administration Express Online Help

Online help for Administration Express in the Netscape Navigator browser opens near the end of the help contents. Online help for Administration Express in the Internet Explorer browser opens near the beginning of the help contents. Users must scroll to view the desired help topic. (521601)


Multiple Email Addresses

When creating or editing a user entry throught the iPlanet Console GUI, only one email address is accepted. (531047) (485161).


Enabling SSL Over LDAP

If you wish to configure your Administration Server use a SSL-enabled Directory Server, do not enable SSL for Admininstration Server and specify an SSL-enabled Directory Server in the same session. After enabling SSL for Administration Server, you must restart, then specify an SSL-enabled Directory Server (532351).

  1. Install a server certificate in Administration Server.

  2. Install a trusted CA certificate in Administration Server.

  3. Enable SSL in the Administration Server.

  4. Restart Administration Server.

  5. Specify an SSL-enabled Directory Server in the Configuration DS tab.

  6. Restart Administration Server.


LC_CTYPE Shell Variable in Solaris 2.6

Console will not start if the LC_CTYPE shell variable is set in Solaris 2.6. To prevent the problem unset LC_CTYPE (533533).





How to Report Problems

If you have problems with iPlanet Product_Name, contact iPlanet customer support using one of the following mechanisms:

So that we can best assist you in resolving problems, please have the following information available when you contact support:





For More Information

Useful iPlanet information can be found at the following Internet locations:


Use of iPlanet Console and Administration Server is subject to the terms described in the license agreement accompanying it.

Copyright © 2000 Sun Microsystems, Inc. Some preexisting portions Copyright © 2000 Netscape Communications Corp. All rights reserved.

Sun, Sun Microsystems, the Sun logo, Java, iPlanet, and all Sun, Java, and iPlanet based trademarks and logos are trademarks or registered trademarks of Sun Microsystems, Inc. in the United States and other countries. Netscape and the Netscape N logo are registered trademarks of Netscape Communications Corporation in the U.S. and other countries. Other Netscape logos, product names, and service names are also trademarks of Netscape Communications Corporation, which may be registered in other countries.


Last Updated May 04, 2001