About Omneon MediaGrid - Harmonic Inc

About Omneon MediaGrid - Harmonic Inc About Omneon MediaGrid - Harmonic Inc

harmonicinc.com
from harmonicinc.com More from this publisher
29.11.2012 Views

System Configuration Tracing an LDAP Problem Use the following procedure to look for the problem. To trace an LDAP problem: 1. Check the LDAP entries to ensure that all information is entered correctly. 2. Check the LDAP error logs for any hints. 3. Compare the entries to a current database entry. 4. Check the UIDs and GIDs of the LDAP entries. These IDs must be greater than 500 for the ContentDirectors to recognize users and groups in the LDAP database. 5. Verify that the following attributes are present for users: • inetorgperson • posixAccount 6. Verify that the following attribute is present for groups: • posixgroup Joining a ContentBridge 2010B/2010C to an LDAP Domain Follow the procedures in this section in order. NOTE: In order to join a ContentBridge 2010B/2010C to an LDAP domain, an LDAP or Open Directory server must already be configured to serve as Samba Primary Domain Controller for the LDAP or Open Directory domain. NOTE: It is not recommended that you switch between ActiveDirectory and LDAP once an authentication method is chosen. Before continuing, make sure the ContentBridge is not configured for ActiveDirectory. Create a ContentBridge Account on the LDAP Server NOTE: This procedure is required for joining a ContentBridge 2010B/2010C to an LDAP domain. To create a ContentBridge account on the LDAP server: 1. On the LDAP server, login as root. 2. Check whether the ContentBridge account with the hostname of the ContentBridge exists. For example, for a ContentBridge 2010B/2010C with a hostname of hbcb205: [root@eng-ldap ~]# /var/lib/samba/sbin/smbldap-usershow hbcb205$ user hbcb205$ doesn't exist NOTE: Make sure to add "$" at the end of the ContentBridge hostname. 3. Create a local user account with the host name of the ContentBridge. For example, for a ContentBridge 2010B/2010C with hostname hbcb205: [root@eng-ldap ~]# adduser hbcb205 116 Installation and Configuration Guide

System Configuration 4. Create a Samba machine account with the hostname of the ContentBridge. You will need to provide the password for the user. For example, for a ContentBridge 2010B/2010C with hostname hbcb205: [root@eng-ldap ~]# /var/lib/samba/sbin/smbldap-useradd -w -i hbcb205 5. Check if the account is created. For example, for a ContentBridge 2010B/2010C with hostname hbcb205: [root@eng-ldap ~]# /var/lib/samba/sbin/smbldap-usershow hbcb205$ NOTE: Configuring different ContentBridges in a MediaGrid cluster with different directory access authentication protocols (for example, ADS, LDAP, and OpenDirectory) is not supported. The following set of steps will reset the authentication mechanism for all ContentBridges in the cluster. Configure Samba Settings on the ContentBridge To configure Samba settings: 1. Connect a monitor and keyboard to the ContentBridge 2010B/2010C. 2. Log on to the ContentBridge using the following user name and password: User name: ovnuser Password: OVN@SvCaUsa 3. Stop smb service. For example, for a ContentBridge 2010B/2010C with hostname hbcb205: [root@hbcb205 ~]# service smb stop 4. Update the following configuration file: /opt/omclb/conf/smb.conf Note the following settings: security = DOMAIN workgroup = password server = add user script = /opt/omutils/bin/omadduser %u a. Replace domain_name with the LDAP domain using the distinguished name of the search base in the LDAP server configuration, which is the name that uniquely identifies an entry in the directory. b. Replace ldap_FQDN with the Fully Qualified Domain Name of the LDAP server. 5. Copy /opt/omclb/conf/smb.conf to /etc/samba/smb.conf. Join the ContentBridge to the LDAP Domain To join the ContentBridge to the LDAP domain: 1. Make sure you are logged in to the ContentBridge, and then enter the following command: net rpc join -U% -S The following example shows the expected result: Joined domain SNV-ENG. [root@hbcb205 ~]# Omneon, Now Part of Harmonic 117

System Configuration<br />

Tracing an LDAP Problem<br />

Use the following procedure to look for the problem.<br />

To trace an LDAP problem:<br />

1. Check the LDAP entries to ensure that all information is entered correctly.<br />

2. Check the LDAP error logs for any hints.<br />

3. Compare the entries to a current database entry.<br />

4. Check the UIDs and GIDs of the LDAP entries. These IDs must be greater than 500 for the<br />

ContentDirectors to recognize users and groups in the LDAP database.<br />

5. Verify that the following attributes are present for users:<br />

• inetorgperson<br />

• posixAccount<br />

6. Verify that the following attribute is present for groups:<br />

• posixgroup<br />

Joining a ContentBridge 2010B/2010C to an LDAP Domain<br />

Follow the procedures in this section in order.<br />

NOTE: In order to join a ContentBridge 2010B/2010C to an LDAP domain, an LDAP or Open Directory<br />

server must already be configured to serve as Samba Primary Domain Controller for the LDAP or Open<br />

Directory domain.<br />

NOTE: It is not recommended that you switch between ActiveDirectory and LDAP once an authentication<br />

method is chosen. Before continuing, make sure the ContentBridge is not configured for ActiveDirectory.<br />

Create a ContentBridge Account on the LDAP Server<br />

NOTE: This procedure is required for joining a ContentBridge 2010B/2010C to an LDAP domain.<br />

To create a ContentBridge account on the LDAP server:<br />

1. On the LDAP server, login as root.<br />

2. Check whether the ContentBridge account with the hostname of the ContentBridge exists. For<br />

example, for a ContentBridge 2010B/2010C with a hostname of hbcb205:<br />

[root@eng-ldap ~]# /var/lib/samba/sbin/smbldap-usershow hbcb205$<br />

user hbcb205$ doesn't exist<br />

NOTE: Make sure to add "$" at the end of the ContentBridge hostname.<br />

3. Create a local user account with the host name of the ContentBridge. For example, for a<br />

ContentBridge 2010B/2010C with hostname hbcb205:<br />

[root@eng-ldap ~]# adduser hbcb205<br />

116 Installation and Configuration Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!