- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - OpenVMS
- >
- Advanced Server - Chaning from Domain to Active Di...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2005 08:16 PM
08-24-2005 08:16 PM
The NT4 domain is being switched off in the coming months and the Alphas need to move over to be part of our Active Directory domain, again just as a member server.
The user manuals don't give too much away about changing domains let alone if it will work with AD.
Anyone got an idea how I do it, is it related to the @SYS$UPDATE:PWRK$CONFIG command.
Thanks
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2005 08:28 PM
08-24-2005 08:28 PM
SolutionBut beware, that changing domain will create a new sharedatabase.
If you have a procedure to recreate shares/protections, thats fine, else I've attached a text from engeeering on how to save the sharedb across domain switsches.
regards Kalle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2005 10:13 PM
08-24-2005 10:13 PM
Re: Advanced Server - Chaning from Domain to Active Directory
I've looked through the note you attached and I'm a bit confused (only a bit not completly).
Step 4 says to delete the file {domain-name}.; but I don't have one named after the domain it's currently residing in. I do have one named after the cluster alias, is this because it is a member server and not a PDC/BDC ?
I understand the rest of it, it's basically just preserving the files that contain the shares and the acls and renaming them back once you have changed domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2005 11:50 PM
08-24-2005 11:50 PM
Re: Advanced Server - Chaning from Domain to Active Directory
if your alphaserver is PDC or BDC, you must have a {domain}. file in
PWRK$LMROOT:[LANMAN.DOMAINS]
If your alpha is neither PDC neither BDC, I'm not sure about that file, but I suppose it have to exists. What does file exist in your directory?
Antonio Vigliotti
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2005 12:08 AM
08-25-2005 12:08 AM
Re: Advanced Server - Chaning from Domain to Active Directory
with either the server's name (standalone) or the cluster-alias.
regards Kalle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-25-2005 12:30 AM
08-25-2005 12:30 AM
Re: Advanced Server - Chaning from Domain to Active Directory
It sounds pretty straight forward to me so I just need to arrange some downtime to try the procedure out.
Thanks for the help
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2005 08:03 PM
09-01-2005 08:03 PM
Re: Advanced Server - Chaning from Domain to Active Directory
I managed to join the domain okay and preserved the shares and acl information. On first appearance everything seemed okay, I could map the shares that were there before. But when I asked my users to do the same they could not map anything.
I then tried a few commands on the Alphas, like Net users and it eventually told me that it couldn't find the domain controller.
Having read other stuff in the forums I think it is possible to get 7.3a working with 2003 but only if you lower the general level of security/encryption etc in your policy.
I've also read that 7.4 (or 7.3b or 7.3b+) is the version needed for full kerberos intergration with 2003.
Does anyone know how I get 7.4, is it free or is it going to cost ?
Cheers
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2005 11:03 PM
09-01-2005 11:03 PM
Re: Advanced Server - Chaning from Domain to Active Directory
http://www1.aclabs.com/masterindex/final_spl_vmsaxp_q105/SPLVAQ105_A93AA_7_3A_ECO4.shtml
for some information
There are a couple of issues with Windows 2003 listed as fixed in the ECO4 release notes.
Purely Personal Opinion
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2005 11:17 PM
09-01-2005 11:17 PM
Re: Advanced Server - Chaning from Domain to Active Directory
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2005 11:58 PM
09-01-2005 11:58 PM
Re: Advanced Server - Chaning from Domain to Active Directory
$@sys$manager:pwrk$define_commands.com
$pwver
Post the output and I'll tell you.
Brad
Software Concepts International
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2005 12:34 AM
09-02-2005 12:34 AM
Re: Advanced Server - Chaning from Domain to Active Directory
Sorry, I missed this question -
The roadmaps are changing - there won't be a 7.4, there won't be Kerberos integration. Engineering is working on porting Samba V3.* to OpenVMS Integrity (and back to Alpha), and eventually port future Samba releases as well. That is where you will need to go to get things like Kerberos integration.
Regards
Brad
Software Concepts International
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2005 03:20 AM
09-02-2005 03:20 AM
Re: Advanced Server - Chaning from Domain to Active Directory
Is it possible to get 7.3A to talk to a Windows 2003 Active Directory without compromising the security policy set on that AD. We have a centrally controlled AD and I have a feeling that anything NT4(ish) is not allowed to join it.
Thanks again !!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2005 03:37 AM
09-02-2005 03:37 AM
Re: Advanced Server - Chaning from Domain to Active Directory
The Advanced Server can act as a BDC in Windows 2000 and Windows 2003 mixed-mode domains, or as a member server in Windows 2000 and Windows 2003 native-mode and mixed-mode domains, in accord withthe limitations imposed by Microsoft on Windows NT V4-compatible servers.
I guess, limitation are crypted password. On Win 2K3 you have to enable uncrypted password inside local domain.
AFAIK there is no security degradation in domain.
Antonio Vigliotti
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-02-2005 09:05 AM
09-02-2005 09:05 AM
Re: Advanced Server - Chaning from Domain to Active Directory
I have AS 7.3A running as a Member Server in a 2003 domain and I didn't need to change anything in 2003 to get it to work. (at least I don't remember having to change anything -- it was a while ago.)
HOWEVER: To Active Directory, it looks like a Win NT4 server so it can't be a DC in native mode.
Since Microsoft does not (afaik) intend to let anyone else use Active Directory, then only Microsoft servers will actually support it. Not Samba; not Pathworks. Blame M$.
You might have some secuity settings causing this, though. Look in the 2003's Local Security Settings -> Local Policies -> Security Options and see if something looks too restrictive.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2005 07:28 AM
09-19-2005 07:28 AM
Re: Advanced Server - Chaning from Domain to Active Directory
In Jan 2005 we changed IP addresses, upgraded to MS-Windows server 2003 from 2000 and moved everyone to new domains. I handled the VMS(7.3-1) cluster/Advanced Sever(7.3A)/TCPIP(5.3) stuff for our cluster of two nodes, txmsba and txmsbb. IT dept handled all the other stuff (Windows, Active Directory, DNS , etc.). I kept a document describing all the things we did to finally get things working. We mainly use the Alpha/OpenVMS system to map shared drives to Windows PCs.
A lot of what I'm including below may not pertain but the most important elements as I recall are:
- the Windows primary domain controller(pdc) must allow "pre-Windows 2000" member servers, like our VMS cluster.
- since the Windows config had several servers in primary/backup roles we had to insure the pdc was desiganted as the "x1b" by making an entry in lmhosts.
As I said, the rest of this may not pertain but I'm taking the shotgun approach here and giving everything we tried.
===============================
Steps Required to Synchronize OpenVMS Advanced Server with
New Primary Domain Controller in Windows 2003 Active Directory
All of the following except PWCONFIG and PWRK$directory changes are required on both txmsbA and txmsbB. Procedures are in cp$disk:[cluster_common].
- Chris Smith removes old DNS entries and adds new ones for txmsba.msb.txdallas.edu(999.131.6.3) and txmsbb.msb.txdallas.edu(999.131.6.4)
- Chris removes txmsbX(alias) from msbAD and adds it to msbDC3, the new primary domain controller(pdc); specify pre-Windows 2000 server option
- Logon OpenVMS/txmsbA, username SYSTEM.
- ADMIN/CONFIG ; Advanced ; [x]Advanced Server only
- ADMIN/CONFIG ; Transport ; [x]DNS [x]LM Hosts
- In pwrk$lanman, edit LMOSTS., adding two lines for PDC:
999.131.3.24 â msb \0X1Bâ #PRE #DOM:msb
999.131.3.24 msbDC3 #PRE #DOM:msb
(string â msb \0X1Bâ must be 22 characters exactly, including quotes)
- Remove old hosts and add new hosts and domain in TCP/IP(@tcpip_set_new_hosts)
- Remove old bind names and add new bind info in TCP/IP(@tcpip_set_new_bind)
- Shutdown and restart TCP/IP(@sys$startup:tcpip$shutdown)
- Shutdown Pathworks (PWSTOP).
- Rename the SAM files before reconfiguring Pathworks:
- in pwrk$lmdomains, rename txmsbx. to txmsbx.old
- in pwrk$lmdatafiles, rename acl. to acl.old, builtin. to builtin.old, lsa. to lsa.old and sharedb. to sharedb.old
- Run Pathworks configuration(PWCONFIG)
- set domain to msb
- set server type to MEMBER
- select YES user/password credentials
- PDC: msbDC3; User: cp-svc; Password: xxxxxxxxxx
- Administrator password: pw$999999
- Rename the SAM files before restarting Pathworks:
(this preserves our old share definitions and permissions)
- in pwrk$lmdatafiles, rename acl.old back to acl. and sharedb.old back to sharedb.
- Restart Pathworks(PWSTART) on txmsbA and txmsbB
- NBSHOW KNBSTATUS msbdc3: identifies â x1bâ PDC
- ADMIN ADD HOSTMAP txdallas\username username (for each programmer; this enables access to OpenVMS personal shares)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-19-2005 07:44 AM
09-19-2005 07:44 AM
Re: Advanced Server - Chaning from Domain to Active Directory
Sorry, my double-quote characters created garbled text in a few critical lines above. Replace the dollar-sign characters below with double-quote in the following lines:
- In pwrk$lanman, edit LMOSTS., adding two lines for PDC:
999.131.3.24 $msb \0X1B$ #PRE #DOM:msb
999.131.3.24 msbDC3 #PRE #DOM:msb
(string $msb \0X1B$ must be 22 characters exactly, including quotes)
- NBSHOW KNBSTATUS msbdc3: identifies $x1b$ PDC
Pat G.