Platinum Edition Using Windows 98

Previous chapterNext chapterContents


- 40 -

Connecting to a NetWare Network


by John West

Using NetWare 3.x and 4.x

Two versions of NetWare are in use extensively today, version 3.x and version 4.x. (The latest version is also referred to as IntranetWare.) A major difference between the two versions is the directory service. Novell version 3.x uses a type of directory service called the bindery. The bindery uses a flat model for storing account information such as usernames and passwords. Each 3.x server has a separate bindery. Therefore, to access resources on more than one 3.x server, you must have an account and password for each one. Version 4.x improved on this system by using a directory service called NetWare Directory Services (NDS). NDS allows more than one server to share account databases. This technology enables you to use the same account to access all servers to which you have rights. NDS is organized into a logical hierarchical tree.

Both NetWare versions now have full native support under Windows 98 via drivers provided by Microsoft, although there are some limitations. In addition to the NetWare 4.x client that Microsoft provides, NetWare also created a client for version 4.x called Client 32.

Using Microsoft's Client for NetWare Networks

The Client for NetWare Networks that comes with Windows 98 provides support for 3.x servers as well as 4.x servers with bindery emulation enabled. Bindery emulation is just what it sounds like. Even though 4.x doesn't use a bindery for directory services, Novell added the capability for it to emulate a bindery so that users who have only NetWare 3.x software support on their workstations can log on (albeit with limited functionality).

After you have installed the Client for NetWare Networks under the Network Control Panel applet, you need to configure the Client so that you can connect to a server. The following steps explain how:

1. Run Control Panel.

2.
Double-click on Network.

3.
Set your Primary Network Logon to Client for NetWare Networks.

4.
Highlight Client for NetWare Networks in the list of installed network components and click on Properties.

Table 40.1 explains the options.

Table 40.1  Configuring the Client for NetWare Networks Options

Option Description
Preferred Server The default server that you are prompted to log on to when you start Windows 98.
First Network Drive The first drive that is used to map to resources on the NetWare server. By default, it's drive F. If you have devices on your computer that use drive letters beyond drive E, you should adjust this parameter so that NetWare and your devices don't try to use the same drive letters.
Enable Logon Script Processing This check box determines whether logon scripts execute when you log on to the NetWare server. Administrators create logon scripts to ensure some level of consistency with the configurations of those users that connect to a server. For instance, in your organization drive H may always map to your home directory on the server. You should not turn off this option unless you've contacted the network administrator first.

After you configure everything and start Windows 98, the logon prompt shown in Figure 40.1 appears on your screen. The first time you connect, you need to verify your logon name; after the first time, Windows 98 remembers it. After you enter the correct credentials, your NetWare logon script will run--if you enabled it as described in Table 40.1--and you will be able to use any resources on the server.

FIG. 40.1 To log on to a NetWare 3.x server, or a 4.x server with bindery emulation, simply specify your user credentials and the name of the NetWare server.

Changing Your Password with Client for NetWare Networks

Microsoft's Client for NetWare Networks does not include functionality to change your password under the Control Panel Password applet. Instead, you must go to a command prompt, change to a drive that is mapped to the System directory on the Novell server, and run the Setpass command. To run it, type SETPASS and enter your old and new passwords.

Using Microsoft's Service for NetWare Directory Services

Logging into a 4.x server with bindery emulation using the Client for Microsoft Networks has some limitations. For the fullest support of 4.x from a Microsoft-supplied client, you'll want to use the Service for NetWare Directory Services. This client enables you to connect to the NDS tree and browse its resources. Also, the logon script in your logon context will run.

To set up your network configuration to allow connectivity to the NDS tree after you've installed Service for NetWare Directory Services (see Chapter 42, "Setting Up a Simple Windows Network") you need to configure the service's parameters. To do so, follow these steps:

1. Run Control Panel.

2.
Double-click on Network.

3.
Set your Primary Network Logon to Client for NetWare Networks.

4.
Highlight Service for NetWare Directory Services in the list of installed network components and click on Properties. Figure 40.2 shows the configuration page.

FIG. 40.2 You need to provide a default tree and context when setting up Service for NetWare Directory Services.

5. Enter your Preferred Tree. This tree is the NDS tree to which you are logging on by default. If you don't specify a Preferred Tree, NDS searches for any existing trees and prompts you to select one when you log on, as shown in Figure 40.3.

FIG. 40.3 When you first log on to NDS, Service for NDS prompts you for a tree if you didn't select one under the Control Panel Network applet.

6. Enter the Workstation Default Context. Because NDS is hierarchical, your account may be several levels down from the top of the tree. To make it easier to browse and refer to resources, you can set this parameter so that when you specify resources, it will be assumed they are located under the context specified. For instance, the full distinguished name for your user account may be .CN=JohnD.OU=Research.O=ABCInc. If your Workstation Default Context is .OU=Research.O=ABCInc, then your logon name would be simply JohnD. When you browse, resources under this context will be displayed first.


TIP: If other users want to log on to your machine, but their accounts are located under a different context, they can still log on. They need to enter their fully distinguished name at the logon prompt. Their logon script will still run. The only way the Workstation Default Context will affect them is that their default context when browsing and accessing resources will be the one you specified in step 6.

You should also specify a preferred server under Client for NetWare Networks. This designation enables the workstation to make initial contact with a server in the NDS tree without having to search the network for one.

When you log on to NDS using Service for NDS, you are prompted for your username and password. Figure 40.4 shows that you can change your Workstation Default Context and Tree by clicking on the Advanced button.

FIG. 40.4 Logging on to NDS with Service for NDS. Notice that because the default context was set to O=JW, it wasn't necessary to use the fully distinguished name of .CN=Admin.O=JW. Instead all that was required was to simply type admin.

You can use this client to log on to a 3.x server as well; choose Log in to a Bindery Server and specify the server name, as shown in Figure 40.5.

FIG. 40.5 As noted on the logon screen, you will not be able to access the NDS tree when you log in to a bindery server.

Changing Your Password with Service for NDS

You can change your password from the Control Panel Passwords applet with Service for NDS. Follow these steps:

1. Run Control Panel.

2.
Double-click on Passwords.

3.
Click on Change Other Passwords.

4.
Select NDS Tree and click Change.

5.
Enter your old password and your new password twice for verification.

Using Novell's Client 32 Software

For the most complete support for NDS, you may want to use Novell's Client 32, which comes with version 4.x. In addition to providing support for all NetWare utilities, Client 32 provides granular access to many settings that make it possible to totally optimize and customize the way you interface with NDS under Windows 98.

After you install Client 32 (see Chapter 42), you need to configure it before you can log on to the NDS tree. Follow these steps:

1. Run Control Panel.

2.
Double-click on Network.

3.
Set your Primary Network Logon to Novell NetWare Client 32.

4.
Highlight Novell NetWare Client 32 in the list of installed network components and click on Properties.

5.
Fill in the properties on the Client 32 tab and the Login tab. Use the information in Tables 40.2 and 40.3 to fill in the details about these options.

Table 40.2  Setting the Options on the Client 32 Tab

Option Description
Preferred Server The server that Client 32 attempts to connect to first. Entering a server name is not necessary if you specify a preferred tree, but it's recommended. Choosing a server eliminates the need to listen for a broadcasting server.
Preferred Tree The tree to which you are attaching in the NDS hierarchy.
If you don't specify a preferred server or preferred tree, the client looks for any broadcasting servers on the network and uses the first one that responds.
Name Context The same as the Workstation Default Context under Microsoft's Service for NDS. It specifies the default context to be used when you log on and when you browse. It does not affect which logon script runs.
First Network Drive The first drive to which Client 32 connects resources. You should set this drive to a letter after F, the default, if your workstation has devices such as hard drives or CD-ROMs that use these letters.

Table 40.3  Configuring Options on the Login Tab

Option Description
Display Connection Page Determines whether the Connection tab gets displayed when you're prompted to logon on during startup. If this option isn't checked, your logon is processed by using the settings set from the Control Panel Network applet.
Log in to Tree The NDS tree you are prompted to log on to by default.
Log in to Server You can specify a server if you know of one in the NDS tree you're trying to attach to or if you're making a bindery connection.
Bindery Connection This option shows that you are connecting to a NetWare 3.x server or to a 4.x server in bindery emulation mode. If you specify a tree, this option is ignored.
Clear Current Connections Any current drive mappings you have is deleted when you attach to a different tree or server or change the security context under which you're connected to the resource (that is, attach as a different user).
Login Script Enables you to specify that a login script other than your user login script should be run. You must have read rights to the login script you specify here.
Profile Script Enables you to specify that a login script other than your profile login script should be run. Again, you must have read rights
Close Script Results Automatically By default, you must click close after your login script runs while logging on. This feature gives you the opportunity to view the processing that occurred in the script. However, the display can become annoying. You can have the login script dialog automatically close after it completes by checking this box.
Run Scripts If you don't want any login scripts to run at all, check this box.
Display Variables Page
%2-%5 NetWare login scripts can have up to four user-defined parameters passed to them. This entry is where you specify the values for the parameters.
Save Settings When Exiting If you check this box, any changes you make to these Login settings when you log on will be saved and used each time you log on from that point forward.

When Windows 98 starts, the Client 32 logon prompt as shown in Figure 40.6 appears. The settings you already specified are enumerated in the respective prompts in this dialog box. You can change any of the settings at this time if you specified that the page on which the setting exists should be displayed.

FIG. 40.6 The number of tabs you see on the Client 32 logon dialog box depends on the settings you selected under the Properties page of Client 32 in the Control Panel Network applet.

Changing Your Password with Novell Client 32

To change your password by using Novell Client 32, follow this procedure:

1. Run Control Panel.

2.
Double-click on Passwords.

3.
Click on Change Other Passwords.

4.
Select Novell NetWare and click Change.

5.
Enter your old password and your new password twice for verification.

6.
Client 32 enables you to synchronize passwords for multiple accounts with which you might be attached. You can change multiple passwords at the same time by selecting the accounts in the NetWare Password Synchronization dialog box shown in Figure 40.7. The caveat is that all the accounts you want to change at the same time must have the same current password.

FIG. 40.7 With Client 32, you can change multiple NetWare account passwords simultaneously.

Configuring NetWare Directory Services

After you configure either Microsoft's Service for NDS or Novell's Client 32, you have support for functionality only NDS provides. You can browse NDS trees by using Network Neighborhood, Explorer, and other third-party browsing tools. You can map drives to NDS volumes. You can install printers in the NDS tree. Figure 40.8 shows an example of browsing the tree. Note that you have context-sensitive options when you right-click an object.

FIG. 40.8 When browsing the LVLab OU, you can see the available printers and volumes.

Using NetWare Utilities

Most NetWare 3.x applications should run under the 32-bit clients provided by Microsoft and Novell. The few that won't are utilities that require support that only the VLM or NETX real-mode clients provide. In most cases, alternative administrative tools are available.

Some NDS applications cannot be used without obtaining the appropriate DLLs from Novell. I recommend using Novell's Client 32 for maximum compatibility if you expect to run NetWare utilities such as NDS Manager or NetWare Administrator for Windows 95. Client 32 is provided with NetWare version 4.x.

Setting Up User-Level Access Control

File and Print Sharing for NetWare Networks lets your Windows 98 machine look like a NetWare server from a user's perspective. You can map to shares and printers, run some NetWare utilities against it, and assign rights based on users and groups from a real NetWare server.

Setting up user-level access control with NetWare is very similar to setting it up with NT (see the previous section "Logging on to a Windows NT Network" for more details). The following steps show the process.


NOTE: NetWare-based user-level security cannot be used with Novell's Client 32 for accessing files on Windows 98 workstations that are shared with File and Print Sharing for NetWare Networks or for actually sharing the resources on a machine with Client 32 installed.[dagger]

To set up user-level access control for NetWare, follow these steps.

1. Run Control Panel

2.
Double-click on Network.

3.
If you don't see File and Printer Sharing for NetWare Networks in the list of networking components, click on File and Print Sharing... and make the appropriate selections depending on whether you want to share files, printers, or both. Close the Control Panel Network applet and reboot to apply your settings. Then start with step 4 at the Control Panel Network applet.

4.
Click on the Access Control tab.

5.
Select User-Level Access Control and specify the NetWare server to whose users and groups you will assign rights on your computer. If you are installing the NetWare client itself for the first time, you are warned that Windows 98 can't confirm that the NetWare server is available, as shown in Figure 40.9.

FIG. 40.9 When you install the NetWare client and File and Print Sharing for NetWare networks at the same time, you get this message because the workstation won't be able to connect to a NetWare server until it reboots.


NOTE: If you specify a 4.x server, only the users and groups in the bindery context will be listed and available to assign rights to.[dagger]
6. Reboot.

Choosing the Browse Method  

After File and Print Sharing is installed, you need to choose how your Windows 98 machine will be located, or browsed, by users. You have two options: workgroup advertising or SAP advertising, as shown in Figure 40.10. Table 40.4 gives details on making this selection.

FIG. 40.10 You can choose to have your Windows 98 machine that is acting as a NetWare server browsed using either workgroup advertising or SAP advertising.

Table 40.4  Choosing Workgroup Advertising or SAP Advertising

Option Description
Workgroup advertising Workgroup advertising enables your machine to be browsed by using the standard method any other Windows machine uses to broadcast itself. For example, if all workstations in a workgroup are called ABC, your NetWare server will show up in this workgroup as well. Workgroup advertising is your best option if you're working in an environment with only Windows machines and you don't need to run utilities such as SLIST. It takes up much less bandwidth on a network. You have four settings: Disabled means you're not using this type of advertising; Enabled: May be a Master means that if no other computers are keeping track of the machines in the workgroup, this one will; Enabled: Preferred Master means that this computer will keep track of the machines in the workgroup by default; and Enabled: Will Not Be Master means that this computer will never keep track of the other machines in the workgroup. If this workgroup contains NT machines, you should choose Enabled: Will Not Be Master.
SAP advertising SAP advertising is the native method NetWare servers use to make themselves known on the network. If you are using DOS-based clients or you need to run utilities such as SLIST, SYSCON or others against the Windows 98 machines, use SAP. This protocol is known for being bandwidth intensive, so unless you absolutely need it, workgroup advertising is your better choice.

Assigning Permissions to Shares and Printers  File and Print Sharing for NetWare Networks enables you to assign rights to resources on your workstation, using users and groups that have been created on a real NetWare server. As a result, users have to know the username and password of their account only on the actual NetWare server. When assigning rights, Windows 98 uses two security contexts to enumerate the user and groups from the bindery on the NetWare server. If you're logged on, Windows uses the account with which you're connected to the server to read the bindery information. However, if you're not logged on to the NetWare server, there must be an account called windows_passthru on the server. If the account is missing, Windows 98 does not have the permissions to connect to the server and read the bindery. Instead, you are prompted to log on to the server when you try to assign rights. To assign rights to a folder or printer, right-click on it and choose Sharing (see Figure 40.11).

FIG. 40.11 You need to specify not only the share name for the printer or directory but also who will have what access.

To share a resource, click the Shared As option, assign a Share Name (no spaces), and give the share an optional Comment that will be displayed when a user browses the resources on the machine. Then you need to assign rights to users and groups. For printers, you can grant either Full Access or No Access to users and groups. Folders, however, can have more granular rights. Table 40.5 shows the available rights:

Table 40.5  Assigning Rights to File-Based Resources

Option Description
Read Only A user can list the files in the folder and read them, but cannot make any modifications.
Full Access A user has all possible rights to a folder. This option is not recommended for security reasons. Instead, assign custom rights as needed.
Custom You can selectively choose to assign any combination of the rights shown in Figure 40.12 when you select Custom. Most of the rights are obvious; however, there are a couple of things to clarify. Write to Files doesn't give a user permission to Delete a file, and List Files only allows a user to see what files are there but doesn't allow him or her to read the files.


CAUTION: The Supervisor account on the NetWare server automatically has full rights to any shares you create on your Windows 98 client using File and Print Sharing for NetWare Networks even if you explicitly specify fewer rights when you assign permissions.

After the resource has been shared, a hand appears under the resource's icon, as shown in Figure 40.13.

FIG. 40.12 The Custom option enables you to assign specific rights.

FIG. 40.13 Windows 98 displays a hand under resources that have been shared.

A significant limitation with File and Print Sharing for NetWare Networks is that you can assign rights to users on only one NetWare server. In other words, if you have server JWSERV and server FINANCE, you can't assign users from both servers rights to your WebSupport share. Another limitation is that you can't have File and Print Sharing for Microsoft Networks and File and Print Sharing for NetWare Networks running on the same machine, because they use totally different protocols. Microsoft Networking uses the SMB protocol, whereas NetWare uses the NCP protocol. 


Previous chapterNext chapterContents


© Copyright, Macmillan Computer Publishing. All rights reserved.