Documentation

Netscape Console 4.23 
for Windows NT and Unix


These release notes contain important information about Netscape Console 4.23. Please read these notes before using the product.

Installation Instructions and Release Notes for all 4.x versions of Netscape servers are available online at this location: http://docs.iplanet.com/docs/manuals/console.html. or http://home.netscape.com/eng/server/.

Use of this product is subject to the terms detailed in the license agreement accompanying it.

Netscape Console incorporates compression code by the Info-ZIP group. There are no extra charges or costs due to the use of this code, and the original compression sources are freely available from ftp://ftp.cdrom.com/pub/infozip/ on the Internet.

The purpose of the Console 4.23 was to incorporate new components to the 4.2, 2001 build. The 4.23 release was shipped with Directory Server 4.14.

To determine which build of Netscape Console 4.2 you have installed, do the following:

  1. If Console is not running, start Console
  2. In the Console Navigation Tree, single click the Netscape Administration Server icon to highlight
  3. The value of the Build Number field reveals which build is installed


The release notes contain these explanations:

What's New in This Release

Netscape Console provides a unified administration interface to all the intranet, extranet, client, and server software under an administrator's control. The 4.23 version of Netscape Console includes the Administration Express feature, and a Perl script for automatically changing the IP address of the Administration Server host.

Administration Express

The Administration Express page is an HTML based server management console. The Administration Express page allows you to quickly start or stop servers, or to view server logs and configuration data without having to launch Netscape Console. For more information, see the online manual located at http://help.netscape.com/products/server/console/console.pdf.

Perl script for IP address changes

This Perl script is useful when the IP address for the Administration Server host changes. The script automatically makes the appropriate IP address change in both the Configuration Directory as well as in the Administration Server configuration. For more information, see the online documentation located at http://docs.iplanet.com/docs/manuals/console/42/html/app_tool.htm#1011091.

Certificates using wildcards are accepted

You can now install certificates that use wild characters (such as *.airius.com). When using server certificates containing wild characters, keep the following in mind (390149):

Potential Problems and Solutions

This section describes the following known problems and related solutions:

Installation

Loss of Network Connection

If you lose a network connection while Netscape Console is running, Netscape Console may become inoperable. Re-establish your network connection, then restart Netscape Console. (106714)

Admin Server Cannot Locate Directory Server

If you are running Windows NT, Netscape Directory Server may start up after Netscape Administration Server. If this happens, Administration Server will not be able to retrieve configuration information from the directory. To solve the problem, restart Netscape Administration Server from the Windows NT Services Control Panel. (394281)

Login Window Is Hidden

When starting Netscape Console using some window managers (Enlightenment, WindowMaker, or Gnome), the Login window may be hidden behind the Netscape Console splash screen, and you will not be able to log in (345545). As a workaround, start Netscape Console at the command line by entering startconsole -x nologo.

Proxied Administration Not Supported

Netscape Console 4.1 does not support proxied administration.

Setting Access Permissions for a Server

You can grant or deny server access to an individual user, but you cannot grant or deny server access to a group. If you select a server in the Netscape Console navigation tree, and attempt to use the Set Access Permissions command to specify a group of users, the permissions you set will not work as expected. (337487)

This is caused by an incorrectly defined Access Control Instruction (ACI) under o=NetscapeRoot. To work around this problem, use ldapmodify to patch this ACI with the following LDIF content:

dn: o=NetscapeRoot 
changetype: modify 
delete: aci 
aci: (targetattr="*")(version 3.0; acl "Enable Group Expansion"; allow (read, 
search, compare)groupdnattr="ldap:///o=NetscapeRoot?uniquemember?sub";) 
- 
add: aci 
aci: (targetattr="*")(version 3.0; acl "Enable Group Expansion"; allow (read, 
search, compare)groupdnattr="uniquemember";)
If you are unfamiliar with ldapmodify and LDIF, refer to the Netscape Directory Server Administrator's Guide.

Setting Access Permissions for a Server Task

If you create an ACI rule to grant or deny access to a server task, the rule will not take effect until you restart both the server (such as Directory Server or Messaging Server) as well as it's Administration Server. (345956, 342786)

Specifying Multiple User Directories for Failover Support

When you specify more than one User Directory for failover purposes, do not use carriage returns to separate directory host names. If you use carriage returns, you'll get an error message. Instead of carriage returns, use spaces to separate host names. (345731) Example: Eros.Airius.com:389 Zeus.Airius.com:389

Server Instance Names

Do not use a period (.) in server instance names. If you use a period in a server instance name, Netscape Console will not recognize the server
instance. For example, the server instance msg.airius.com is not acceptable; msg-airius-com is acceptable. (311490)

Non Default Uid

When the default language requires a uid in a form other than the default (user's first initial followed by last name), you must manually override the nsuserformat attribute in the configuration directory. (117507) To change the nsuseridformat attribute:
  1. In the Netscape Console, open the Directory Server that contains the configuration directory you want to modify.
  2. In the Directory Server, click Directory.
  3. Expand the navigation tree to follow this path: NetscapeRoot/[administration domain]/Global Preferences.
  4. In the navigation tree, select Global Preferences.
  5. In the right pane double-click Common.
  6. In the Property Editor window, locate the attribute nsuseridformat and enter one of the following values as appropriate:
  7. Click OK.
  8. Restart Netscape Console.

Changing a User's Password

If you create a user without indicating a password, selecting the user and clicking on the Password button will allow you to assign a value for the user's password attribute. If you try to change this value by clicking on the Password button again, the new value will be stored alongside the old value and the user will have two valid passwords. To work around this: select the user, click on Edit, and then enter and confirm the new password in the Edit Entry dialog box. Alternatively, you can choose to assign a password when creating a new user. If you have already created a user with multiple passwords, perform a new search for the user and enter a new password using the Edit or Password button. This will discard any old values and assign a single password for the user

8-bit Characters

When creating a new user or editing a user's personal data, do not use 8-bit characters in the First Name and Last Name fields. If you use 8-bit characters in the First Name or Last Name fields, the user ID is not automatically generated for you. Instead, use ASCII characters to enter the user's personal data. (117507)

Windows NT with DHCP

You cannot install Administration Server 4.0 or Directory Server 4.0 on Windows NT with DHCP. As a workaround, you can install successfully using a static IP address. (105984)

Using Solaris

Using HP-UX

Using AIX with jre 1.1.6

If Netscape Console crashes upon startup, you must disable JIT. (316827) To disable JIT, invoke startconsole with the -nojit option.

Using Linux

If Netscape Console hangs during log in, it may be due to a problem with NIS (349906). As a workaround, in /etc/nsswitch.conf, modify the nis and dns lookup ordering in the the hosts entry. Make sure dns comes before nis.

Opening Administration Server Results in Blank Window

If you log into Netscape Console using Administration Server 4.0 or 4.1, and then try to open an Administration Server 4.2 that is SSL-enabled, the Administration Server 4.2 window will be blank. (353341) The problem is due to an incompatibility between Netscape Console 4.2 and pre-4.2 SSL libraries. There is no workaround at this time.

Downloading a server's JAR files to Netscape Console

Generally, a server's JAR files used by Netscape Console are stored in the Administration Server. However, in Netscape Console 4.2, a server's JAR files can be stored on any HTTP server. If, for any reason, you choose to store a server's JAR files in a location other than the default location in the Administration Server, do not password protect the JAR files. Password protection may cause authentication to fail, and you will not be able to download the files to the Netscape Console. (357280)

Improving Administration Express Performance

If the host computer for a server registered against the Configuration Directory is experiencing network problems, there could be a long delay when the Administration Express page tries to contact the server and create a status page. (355354) To improve Administration Express performance, in the file <Server_Root>/admin-serv/config/adm.conf, add the following entry:

ExpressCGITimeout: x

In this entry, x is an integer representing how long (in seconds) Administration Express should continue trying to reach the remote server before timing out.

Can't Start/Stop Local Windows NT Servers using Administration Express

When using Administration Express on Windows NT, you cannot start and stop servers on the local machine. You can view, start, and stop servers on UNIX machines and other Windows NT machines on the network. If you want to start or stop a server on the local machine, use the command line or Netscape Console. This problem does not affect you if you are using Administration Express on UNIX. (389488)

Enabling SSL on Directory Server 4.x using Console 4.2

After installing Administration Server and Console 4.2, if you enable SSL on Netscape Directory Server 4.x, the directory server won't start. You will see the following message in the error log:

"Failed to set SSL cipher preference information: unknown cipher tls_rsa_export1024_with_rc4_56_sha!"

This message is generated because Console 4.2 includes two additional cipher suites that Directory Server 4.x does not recognize.

To work around this problem, do the following with encryption enabled and the directory not running:

  1. Edit the dse.ldif file located in <server-root>/slapd-<server-name>/config/ as follows:

  2. Remove the two "-tls_" strings from the dse.ldif file. These strings exist under the attribute name "nsssl3ciphers," which is found in the "cn=encryption, cn=config" node beneath the affected server instance SIE.
  3. Start the Directory Server from the command-line with start-slapd.
Once you have modified dse.ldif, you can disable and enable encryption for Directory Server by manually modifying the "security on/off" setting in slapd.conf. If you use Console to change your encryption settings or disable and then re-enable encryption, you will have to edit dse.ldif again.

On Windows NT, End-User Page Not Accessible with SSL

On Windows NT, if you enable SSL on the Directory Server, you will not be able to access the End-User Page (see illustration).

Using Netscape Console with Netscape Certificate Server 1.x

When you use a Netscape 4.x server to request a server certificate from a Netscape Certificate Server 1.x, do not use wildcards, punctuation marks, or other special characters when specifying the server host name. If you do, Certificate Server will display the following message "Invalid DER encoding" when the certificate is submitted. If you must use wildcards (for example www.airius|netscape.com), then you must make a special note to the CA when you submit the certificate request. The following image illustrates how you can submit a special note to the CA:


 

Using Netscape Console with Netscape Certificate Management System 4.x

If you specify a URL when using Console's Certificate Request Wizard with Netscape Certificate Management System 4.x (CMS), you must include a port number. For example, if CMS is running on port 443 of the cmsServer.airius.com host, you must enter the URL as https://cmsServer:443. If you enter https://cmsServer, you will not be able to automatically request a certificate. (392984)

Using an external token to store certificates

If you use an external token or smart device to store multiple security certificates, the device may run out of storage space. This happens when you repeatedly use the Certificate Setup Wizard to generate certificate requests without deleting previously installed public or private keys. (347448) To avoid this problem, follow the instructions provided by the external device manufacturer to first back up your existing certificate(s), and then to clear the device's memory.

Installing a FORTEZZA PKCS #11 Module on Windows NT

If the FORTEZZA PKCS #11 module you want to install is a DLL file (or shared library) and not a JAR file, do not use the "Manage PKCS #11" or "Add PKCS #11" commands in Netscape Console. If you use the Netscape Console graphical interface, you will not be able to activate FORTEZZA ciphers. Instead, use the modutil command line utility located at <server_root>/shared/bin/modutil.
To install a FORTEZZA PKCS #11 Module DLL File:
  1. Locate the server instance for which you want to install the PKCS #11 module.
  2. Open a terminal window.
  3. Go to the Administration Server's configuration directory located at <server_root>/admin-serv/config.
  4. At the prompt, enter this command: <server-root>/shared/bin/modutil -dbdir . -create

  5. This creates the required security module database file (secmod.db) in the Administration Server's configuration directory.
  6. At the prompt, enter this command:

  7. <server_root>/shared/bin/modutil -dbdir . -add <module_name> -libfile <library_file> -nocertdb

    <library_file> specifies the path to the DLL or other library file containing the implementation of the PKCS #11 interface module.

    <module_name> specifies the name of the PKCS #11 module (you specified this in Step1 when you installed the drivers).

For example, if you are installing a Litronic token, you would enter:
<server_root>/shared/bin/modutil -dbdir . -add CryptOS -libfile core32

For detailed information about modutil, see modutil Appendix B, "Administration Server Command Line Tools" in the Netscape Console documentation.

Logging in as Directory Manager

If you log in to Netscape Console using the DN cn=directory manager, your font display preferences will not be saved. (341686)

Expired SIE passwords block access to Administration Server tasks

If a password expiration policy is enabled in Directory Server, and a connected Administration Server's SIE passwords expire, you will not be able to access the connected server. (343369) As a workaround, you can delay the expiration date of the Administration Server passwords. Use the ldapmodify utility to change two administrative entries. In the following example, replace <hostname> with the hostname of the server, and finish the command with Ctl-Z:

ldapmodify -D "cn=directory manager" -w password
dn: uid=Configuration Administrator, ou=admin, ou=Topology Management, o=NetscapeRoot
changetype: modify
replace: userpassword
userpassword: <newpassword>
-
replace: passwordexpirationtime
passwordexpirationtime: 20011231000000

dn: cn=admin-serv-<hostname>, cn=Netscape Administration Server, cn=Server Group, cn=<hostname>, ou=<hostname>.
o=NetscapeRoot
changetype: modify
replace: userpassword
userpassword: <newpassword>
-
replace: passwordexpirationtime
passwordexpirationtime: 20011231000000

Searching a Large User Directory

If you use the Search interface to list all users in a large directory (for example, more than 1000 entries), the search may return 0 results. (341275) To improve search results, simply restrict your search criteria.

Full Thread Dump

If you're trying to run the command line, and a segmentation violation occurs resulting in a full thread dump output, you may have an incompatible version of JRE or JDK in your path. Adding the following lines to the adminconfig script will eliminate this problem:
JAVA_HOME=./bin/base/jre
export JAVA_HOME
CLASSPATH=
export CLASSPATH
You can manually edit the admconfig script located at /bin/admin/admconfig, or you can enter these lines at the command line before running ./bin/admin/admconfig.

Using SSL

Using "objectClass: mailgroup" in Netscape Messaging Server 3.6

Changing Configuration Directory Server Information

Changing User Directory After SSL is Enabled on Windows NT

If you want to change your User Directory you must do so before SSL is enabled on Directory Server. On the Windows NT platform, changing your User
Directory after SSL is enabled on Directory Server results in a ugdsconfig.exe application error (530500).

Creating 8 bit Characters in Console

Some 8 bit characters, for example, Ê and Ë, cannot be created in Console input fields.
To use these characters do the following:
  1. Open a text editor of your choice
  2. Create the 8 bit character
  3. Copy the 8 bit character you created
  4. Paste the character, using crtl-v, into the appropriate Console input field (529527)

Where to Go for Other Information

For installation instructions, see the Install.htm file for the server you're installing. Installation Instructions and Release Notes for all Netscape servers are posted at this location: http://home.netscape.com/eng/server/

If you can't find the information you need, contact Technical Support.


Copyright © 2001 Sun Microsystems, Inc. Some preexisting portions Copyright © 2000 Netscape Communications Corp. All rights reserved.