Thursday, September 29, 2005

Password Sync from Linux to Windows using

Copy pam_sso.rhl from the unix/bins directory in the SFU disk to /lib/security/pam_sso.so
chmod 755 on /lib/security/pam_sso.so

Copy sso.cfg from the unix/bins directory in the SFU disk to /etc/sso.conf
chmod 600 on /etc/sso.conf

Edit SYNC_HOSTS to reflect the windows NIS Server


Use a UNIX text editor to open the etc/pam.d/system-auth file, and then locate the following line:
password required /lib/security/pam_cracklib.so retry=3

After locating the line, add the following line:
password required /usr/lib/security/pam_sso.so.1

Locate and then delete the following line:
password required /usr/lib/security/pam_deny.so


Now you can change the password using "passwd username"

NIS client on Linux - Fedora Core4

We will be using NIS server from Windows that is previously installed and configured

edit /etc/yp.conf to include domain line Ex."domain techvim server 192.168.0.50"

check if the domainname matches your domain name Ex."techvim"
else insert a domainname line in /etc/init.d/ypbind
Ex."domainname techvim"

restart the ypbind service

check "ypcat passwd"

modify /etc/nsswitch.conf to include nis
modify /etc/passwd by typing in "+::::::" as the last line

To automatically create home directories on the machine include the line
session required pam_mkhomedir.so skel=/etc/skel/ umask=0077
in /etc/pam.d/system-auth before all the session lines

Installing MS Services For UNIX 3.5 on Windows 2003 Server Std

Install with default settings


Note:* Passwords for users should be reset after unix attributes for the user are
set

Open up Microsoft Windoes Services for UNIX console and click on Server for NIS -> techvim and Apply the settings

In Password Synchronization inselect Windows to UNIX sync and select UNIX to Windows sync. In Advanced, add the computer name and IP address of the UNIX machine.


Change Password Web Part for WSS on Windows 2003 Server Std

For Installing and configuring Web Part

Install ITaCS Change Password Web Part

Create a new Web Part Page

Browse to Virtual Server Gallery and add Change Password Web Part

Click on "Offnen Sie den Toolbereich"

Under Settings enter the Domain Name and change the Language

Add a link to the home page


For changing the Security Policy Settings

Go to Active Directory Users and Computers -> right-click on the domain and select properties -> Go to Group Policy and select Default Domain Policy -> Edit... -> Browse to Computer Configuration -> Windows Settings -> Security Settings -> Account Policies -> Password Policy
and modify the settings to

Enforce password history 1
Maximum password age 0
Minimum password age 0
Minimum password length 7
Password must meet complexity requirements Enabled
Store passwords using reversible encryption Disabled

Asterisk | The Open Source PBX

Asterisk | The Open Source PBX A IP Telephony site is worth taking a look at using the inexpensive Intel hardware.

Wednesday, September 28, 2005

RyanVM's MSFN Files Page

RyanVM's Windows Updates has all the updates and service packs released til date in a convenient package that can be slipstreamed using nLite software to make a Windows Install CD

Home of nuhi - nLite homepage

nLite for slipstreaming Service packs, Hotfixes, Drivers, Tweaks and Uninstalled Installs for Windows 2000, XP and Server Operating Systems.

This is a great tool for making bootable Windows Installation CD's and goes with the RyanVM's Update Packs.

Windows 2003 Std Server w/PDC and WSS

Install 2003 with default options except for Networking settings.
Select Custom Settings, set a static IP for the ethernet.

After installation make sure that you set the primary DNS suffix
Go to Start -> My Computer -> Properties -> Computer Name -> Change -> More and type in the primary DNS suffix Ex. "techvim.com" Click OK 4 times and restart the PC

Install all the available updates to Windows 2003 Server

Installing a DNS Server

  • In Manage Your Server Console, Click Add or Remove a role
  • Select DNS Server
  • Make sure that youve set a Static IP for the machine, have the primary DNS suffix set to the domain name and DNS server pointing to the local machine

Configure a DNS Server Wizard will start

  • Select Create forward and reverse lookup zones
  • Select Yes, create a forward lookup zone now
  • Select Primary zone
  • Type in your domain name Ex. "techvim.com" in the Zone name
  • accept the default for the Zone File
  • Select allow both nonsecure and secure dynamic updates (for AD to register itself)
  • Select Yes, create a reverse lookup zone now
  • Select Primary zone
  • Type in Network ID Ex. "192.168.0"
  • accept the default for the Zone File
  • Select allow both nonsecure and secure dynamic updates (for AD to register itself)
  • Select No, it should not forward queries


Promoting the server to a Domain Controller

  • In Manage Your Server Console, Click Add or Remove a role
  • Select Domain controller (Active Directory)

The Active Directory Installation Wizard will start

  • Select Domain controller for a new domain
  • Select Domain in a new forest
  • Type in the Full DNS name for new domain Ex. "techvim.com"
  • Type in the NetBIOS name Ex. "TECHVIM"
  • Leave defaults for the Database and Log folders
  • Leave defaults for the Shared System Volume
  • Select Permissions compatible only with Windows 2000 or Windows 2003 Server operating systems
  • Enter a restore mode password
  • It will take a while to populate the AD

Installing Application Server for WSS

  • In Manage Your Server Console, click Add or Remove a role
  • Select Application Server
  • Select Enable ASP.NET

Install Windows SharePoint Services

  • Select Typical Installation