Chapter 9. Authentication in ThinLinc
• Create a default group to be used for ThinLinc Users
All users of a ThinLinc server need to have a default posixGroup assigned to their user objects. This
group can be created by TLNC.
• Create indices needed for proper performance
For proper performance, a few indices on LDAP attributes are needed. The Novell Configurator can
create the needed indices.
9.3.1.2. Using the ThinLinc Novell Configurator
TLNC is normally used only a few times - at installation, and when new eDirectory servers are added to
the network. It can be run at any time to verify that all settings are correct. It is recommended to run
TLNC after each upgrade of ThinLinc, so new recommended settings in eDirectory can be applied. Also
run TLNC when new eDirectory servers are added, to correctly configure attribute mappings and indices.
To run TLNC, point your web browser to your ThinLinc server, port 1010, as documented in Chapter 16.
Look for the menu with the text Novell Configurator and click on it. You have now entered the TLNC.
Select the Configure submenu, and start by entering values into the fields provided by the web page you
just entered.
• The eDirectory Server Hostname should be the fully qualified hostname of one of your eDirectory
servers. It doesn’t matter which server you choose, TLNC will read out the list of LDAP servers from
the first server, and configure all of them.
• Activate the Connect using SSL checkbutton to communicate encrypted with the eDirectory server.
Note: You must use the fully qualified hostname, i.e., a hostname on the form server.example.com in
the eDirectory Server Hostname field, or SSL connections will fail.
• Normally, you don’t have to enter anything into the Search base field, since most eDirectory sites have
a structure that enables TLNC to work well when searching from "". For sites that have several LDAP
trees below the root, this setting may be of need.
• Enter the DN of the administrative user into the Novell Admin User DN field. The DN should be
entered in LDAP-form, with comma signs between the different parts of the DN, not periods.
• Finally, enter the password of the administrative user into the Password of Admin User field.
Now press the Start Configuration button. The Novell Configurator will now communicate with your
eDirectory server to see what needs to be done. It will then present a page where the you can see the
status of the integration between the ThinLinc cluster and eDirectory. Areas where action is needed are
marked with red.
Inspect the data presented on the page. In the areas where action is needed, TLNC will have activated the
checkbuttons for the action that needs to be taken. Verify that all checked actions are things you want,
and then press the Execute selected actions button. The TLNC will now communicate further with
your eDirectory server to execute the actions you selected.
When all actions are executed, the same page will show up again, with the integration status. Verify that
all went well, and proceed with the actions needed after running TLNC.
93
Comentarios a estos manuales