{"id":512,"date":"2012-10-17T11:10:32","date_gmt":"2012-10-17T16:10:32","guid":{"rendered":"http:\/\/www.thedarktimes.us\/wordpress\/?p=512"},"modified":"2012-10-17T11:10:32","modified_gmt":"2012-10-17T16:10:32","slug":"recreating-certificates-on-oes-migrating-to-a-new-server-and-checking-status-in-a-nutshell","status":"publish","type":"post","link":"https:\/\/www.thedarktimes.us\/wordpress\/oes2-linux\/recreating-certificates-on-oes-migrating-to-a-new-server-and-checking-status-in-a-nutshell\/%20","title":{"rendered":"Recreating Certificates on OES, migrating to a new server, and checking status (in a nutshell)"},"content":{"rendered":"<p><strong>Recreating Certificates on OES, migrating to a new server, and checking status (in a nutshell)<\/strong><\/p>\n<p><strong>Author Info<\/strong><\/p>\n<p>3 October 2012 &#8211; 11:25am<br \/>\nSubmitted by: <a title=\"View user profile.\" href=\"http:\/\/www.novell.com\/communities\/user\/67493\">shawniverson2<\/a><\/p>\n<p><strong>Preparation <\/strong><\/p>\n<p><strong>Step 1 &#8212; Become One with Your Environment<\/strong><\/p>\n<p>Understand and document your environment.<\/p>\n<p>i.e. IP Addressing, services running on old <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/2314\">server<\/a>, <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/3276\">eDirectory<\/a> structure, etc.<\/p>\n<p>This information is different in every environment.<\/p>\n<p><strong>Step 2 &#8212; Be Your Environment<\/strong><\/p>\n<p>Fully back up your current environment.<\/p>\n<p>These steps vary depending on your backup solution.<\/p>\n<p><strong>Step 3 &#8212; Focus and Meditate on Your Environment<\/strong><\/p>\n<p>Practice with OES in a test environment first until you are comfortable. A good technique is to restore\/clone your current environment into a sandbox, snapshot it, and practice upgrading until you get it right. This is also a good way to verify that restores from backup will work as well \ud83d\ude09<\/p>\n<p>Again, steps here vary depending on your backup and cloning solution.<\/p>\n<p><strong>Execution<\/strong><\/p>\n<p><strong>Step 1 &#8212; Where&#8217;s my CA?<\/strong><\/p>\n<p>Make sure you know where your Certificate Authority is located.<\/p>\n<p>A quick way to determine which server is the CA is to go to <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/2869\">iManager<\/a> &#8211;&gt; <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/2961\">Novell Certificate Server<\/a> &#8211;&gt; Configure Certificate Authority<\/p>\n<p>Look at the <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/1473\">host server<\/a> entry.<\/p>\n<p><strong>Step 2 &#8212; Is my CA valid?<\/strong><\/p>\n<p>iManager &#8211;&gt; Novell Certificate Server &#8211;&gt; Configure Certificate Authority &#8211;&gt; Certificates &#8211;&gt; Check each cert and click Validate<\/p>\n<p>If your CA certs are not valid, you will need to fix this before proceeding as you will not be able to generate server certificates.<\/p>\n<p>The procedure to fix this problem is to recreate your CA and generate new CA certificates.<\/p>\n<p>See <a href=\"http:\/\/www.novell.com\/support\/kb\/doc.php?id=3618399\" target=\"_blank\">How do I move the Organizational CA to another server?<\/a> under Option II for more information.<\/p>\n<p><strong>Step 3 &#8212; Are my server certs valid?<\/strong><\/p>\n<p>iManager &#8211;&gt; Novell Certificate Access &#8211;&gt; Server Certificates<\/p>\n<p>Use the magnifying glass to select your server and validate your certificates.<\/p>\n<p><strong>Step 4 &#8212; Recreating server certs (if not valid)<\/strong><\/p>\n<p>I highly recommend this procedure. OES scatters the certificates all over the place for many services. Updating them in eDirectory\/iManager is not enough! Why not let this script do it for you?<\/p>\n<p><a href=\"http:\/\/www.novell.com\/communities\/node\/5704\/certificate-recreation-script-oes1-and-oes2\" target=\"_blank\">Certificate Re-creation Script for OES1, OES2 and OES 11<\/a><\/p>\n<p><strong>Step 5 &#8212; Migrating to a new server<\/strong><\/p>\n<p>Two methods generally exist for this. Transfer ID and Server Consolidation. Your path will depend on your unique situation and requirements.<\/p>\n<p>The Migration Tool Administration Guide from Novell is your friend. Download the guide from Novell for you particular version of OES.<\/p>\n<p>Note from step 1: If the server you are migrating from is your CA, you&#8217;ll need to migrate the CA as well! This is not covered in the guide!<\/p>\n<p>See <a href=\"http:\/\/www.novell.com\/support\/kb\/doc.php?id=3618399\" target=\"_blank\">How do I move the Organizational CA to another server?<\/a> Option I for more information.<\/p>\n<p><strong>Step 6 &#8212; Checking status<\/strong><\/p>\n<p>Checking status will depend on what services you are running on your server.<\/p>\n<p><strong>Tip 1:<\/strong> Check running services<\/p>\n<p>Using service servicename status or rcservicename status will tell you if a service is running.<\/p>\n<p>(Look in \/etc\/init.d for a full list of services on your server. Note that some services may be disabled.)<\/p>\n<p><strong>Tip 2:<\/strong> Check your logs<\/p>\n<p>OES scatters logs all over the place. Here are some common places.<\/p>\n<p>\/var\/log<br \/>\n\/var\/opt\/novell\/log\/servicename<br \/>\n\/var\/opt\/novell\/servicename\/log<\/p>\n<p><strong>Tip 3:<\/strong> Monitor your server using top for <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/521\">CPU<\/a>, Process, and Memory in realtime<\/p>\n<p><strong>Tip 4:<\/strong> Use Remote Manager<\/p>\n<p><a title=\"http:\/\/myservername:8008\" href=\"http:\/\/myservername:8008\">http:\/\/myservername:8008<\/a><\/p>\n<p><strong>Tip 5:<\/strong> Use iMonitor for eDirectory health<\/p>\n<p><a title=\"https:\/\/myservername:8030\" href=\"https:\/\/myservername:8030\">https:\/\/myservername:8030<\/a><\/p>\n<p><strong>Tip 6:<\/strong> Monitor disk usage<\/p>\n<p>Use df -h from a <a href=\"http:\/\/www.novell.com\/communities\/glossary\/term\/791\">shell<\/a>\/terminal for a quick glance<\/p>\n<p><strong>Step 7 &#8212; Download the Docs for More Information<\/strong><\/p>\n<p>Novell keeps extensive <a href=\"http:\/\/www.novell.com\/documentation\/oes11\/oes11_toc\/data\/index-stand.html\" target=\"_blank\">documentation<\/a> on OES on nearly every topic related to OES. Get your copy of the documentation!<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>Disclaimer:<\/em><\/strong><em> As with everything else at Cool Solutions, this content is definitely not supported by Novell (so don&#8217;t even think of calling Support if you try something and it blows up). <\/em><\/p>\n<p><em>It was contributed by a community member and is published &#8220;as is.&#8221; It seems to have worked for at least one person, and might work for you. But <span style=\"text-decoration: underline;\">please be sure to test, test, test before you do anything drastic with it<\/span>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recreating Certificates on OES, migrating to a new server, and checking status (in a nutshell) Author Info 3 October 2012 &#8211; 11:25am Submitted by: shawniverson2 Preparation Step 1 &#8212; Become One with Your Environment Understand and document your environment. i.e. IP Addressing, services running on old server, eDirectory structure, etc. This information is different in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50,25,29],"tags":[],"class_list":["post-512","post","type-post","status-publish","format-standard","hentry","category-oes11","category-oes2-linux","category-oes2-sp3"],"_links":{"self":[{"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/posts\/512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/comments?post=512"}],"version-history":[{"count":1,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/posts\/512\/revisions"}],"predecessor-version":[{"id":513,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/posts\/512\/revisions\/513"}],"wp:attachment":[{"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/media?parent=512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/categories?post=512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thedarktimes.us\/wordpress\/wp-json\/wp\/v2\/tags?post=512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}