
by John West
Two versions of NetWare are in use extensively today, version 3.x and version 4.x. (The latest version is also referred to as IntranetWare.) A major difference between the two versions is the directory service. Novell version 3.x uses a type of directory service called the bindery. The bindery uses a flat model for storing account information such as usernames and passwords. Each 3.x server has a separate bindery. Therefore, to access resources on more than one 3.x server, you must have an account and password for each one. Version 4.x improved on this system by using a directory service called NetWare Directory Services (NDS). NDS allows more than one server to share account databases. This technology enables you to use the same account to access all servers to which you have rights. NDS is organized into a logical hierarchical tree.
Both NetWare versions now have full native support under Windows 98 via drivers provided by Microsoft, although there are some limitations. In addition to the NetWare 4.x client that Microsoft provides, NetWare also created a client for version 4.x called Client 32.
The Client for NetWare Networks that comes with Windows 98 provides support for 3.x servers as well as 4.x servers with bindery emulation enabled. Bindery emulation is just what it sounds like. Even though 4.x doesn't use a bindery for directory services, Novell added the capability for it to emulate a bindery so that users who have only NetWare 3.x software support on their workstations can log on (albeit with limited functionality).
After you have installed the Client for NetWare Networks under the Network Control Panel applet, you need to configure the Client so that you can connect to a server. The following steps explain how:
Table 40.1 explains the options.
| Option | Description |
| Preferred Server | The default server that you are prompted to log on to when you start Windows 98. |
| First Network Drive | The first drive that is used to map to resources on the NetWare server. By default, it's drive F. If you have devices on your computer that use drive letters beyond drive E, you should adjust this parameter so that NetWare and your devices don't try to use the same drive letters. |
| Enable Logon Script Processing | This check box determines whether logon scripts execute when you log on to the NetWare server. Administrators create logon scripts to ensure some level of consistency with the configurations of those users that connect to a server. For instance, in your organization drive H may always map to your home directory on the server. You should not turn off this option unless you've contacted the network administrator first. |
After you configure everything and start Windows 98, the logon prompt shown in Figure 40.1 appears on your screen. The first time you connect, you need to verify your logon name; after the first time, Windows 98 remembers it. After you enter the correct credentials, your NetWare logon script will run--if you enabled it as described in Table 40.1--and you will be able to use any resources on the server.
FIG. 40.1 To log on to a NetWare 3.x server, or a 4.x server with bindery emulation, simply specify your user credentials and the name of the NetWare server.
Microsoft's Client for NetWare Networks does not include functionality to change your password under the Control Panel Password applet. Instead, you must go to a command prompt, change to a drive that is mapped to the System directory on the Novell server, and run the Setpass command. To run it, type SETPASS and enter your old and new passwords.
Logging into a 4.x server with bindery emulation using the Client for Microsoft Networks has some limitations. For the fullest support of 4.x from a Microsoft-supplied client, you'll want to use the Service for NetWare Directory Services. This client enables you to connect to the NDS tree and browse its resources. Also, the logon script in your logon context will run.
To set up your network configuration to allow connectivity to the NDS tree after you've installed Service for NetWare Directory Services (see Chapter 42, "Setting Up a Simple Windows Network") you need to configure the service's parameters. To do so, follow these steps:
FIG. 40.2 You need to provide a default tree and context when setting up Service for NetWare Directory Services.
FIG. 40.3 When you first log on to NDS, Service for NDS prompts you for a tree if you didn't select one under the Control Panel Network applet.
TIP: If other users want to log on to your machine, but their accounts are located under a different context, they can still log on. They need to enter their fully distinguished name at the logon prompt. Their logon script will still run. The only way the Workstation Default Context will affect them is that their default context when browsing and accessing resources will be the one you specified in step 6.
You should also specify a preferred server under Client for NetWare Networks. This designation enables the workstation to make initial contact with a server in the NDS tree without having to search the network for one.
When you log on to NDS using Service for NDS, you are prompted for your username and password. Figure 40.4 shows that you can change your Workstation Default Context and Tree by clicking on the Advanced button.
FIG. 40.4 Logging on to NDS with Service for NDS. Notice that because the default context was set to O=JW, it wasn't necessary to use the fully distinguished name of .CN=Admin.O=JW. Instead all that was required was to simply type admin.
You can use this client to log on to a 3.x server as well; choose Log in to a Bindery Server and specify the server name, as shown in Figure 40.5.
FIG. 40.5 As noted on the logon screen, you will not be able to access the NDS tree when you log in to a bindery server.
You can change your password from the Control Panel Passwords applet with Service for NDS. Follow these steps:
For the most complete support for NDS, you may want to use Novell's Client 32, which comes with version 4.x. In addition to providing support for all NetWare utilities, Client 32 provides granular access to many settings that make it possible to totally optimize and customize the way you interface with NDS under Windows 98.
After you install Client 32 (see Chapter 42), you need to configure it before you can log on to the NDS tree. Follow these steps:
| Option | Description |
| Preferred Server | The server that Client 32 attempts to connect to first. Entering a server name is not necessary if you specify a preferred tree, but it's recommended. Choosing a server eliminates the need to listen for a broadcasting server. |
| Preferred Tree | The tree to which you are attaching in the NDS hierarchy. |
| If you don't specify a preferred server or preferred tree, the client looks for any broadcasting servers on the network and uses the first one that responds. | |
| Name Context | The same as the Workstation Default Context under Microsoft's Service for NDS. It specifies the default context to be used when you log on and when you browse. It does not affect which logon script runs. |
| First Network Drive | The first drive to which Client 32 connects resources. You should set this drive to a letter after F, the default, if your workstation has devices such as hard drives or CD-ROMs that use these letters. |
| Option | Description |
| Display Connection Page | Determines whether the Connection tab gets displayed when you're prompted to logon on during startup. If this option isn't checked, your logon is processed by using the settings set from the Control Panel Network applet. |
| Log in to Tree | The NDS tree you are prompted to log on to by default. |
| Log in to Server | You can specify a server if you know of one in the NDS tree you're trying to attach to or if you're making a bindery connection. |
| Bindery Connection | This option shows that you are connecting to a NetWare 3.x server or to a 4.x server in bindery emulation mode. If you specify a tree, this option is ignored. |
| Clear Current Connections | Any current drive mappings you have is deleted when you attach to a different tree or server or change the security context under which you're connected to the resource (that is, attach as a different user). |
| Login Script | Enables you to specify that a login script other than your user login script should be run. You must have read rights to the login script you specify here. |
| Profile Script | Enables you to specify that a login script other than your profile login script should be run. Again, you must have read rights |
| Close Script Results Automatically | By default, you must click close after your login script runs while logging on. This feature gives you the opportunity to view the processing that occurred in the script. However, the display can become annoying. You can have the login script dialog automatically close after it completes by checking this box. |
| Run Scripts | If you don't want any login scripts to run at all, check this box. |
| Display Variables Page | |
| %2-%5 | NetWare login scripts can have up to four user-defined parameters passed to them. This entry is where you specify the values for the parameters. |
| Save Settings When Exiting | If you check this box, any changes you make to these Login settings when you log on will be saved and used each time you log on from that point forward. |
When Windows 98 starts, the Client 32 logon prompt as shown in Figure 40.6 appears. The settings you already specified are enumerated in the respective prompts in this dialog box. You can change any of the settings at this time if you specified that the page on which the setting exists should be displayed.
FIG. 40.6 The number of tabs you see on the Client 32 logon dialog box depends on the settings you selected under the Properties page of Client 32 in the Control Panel Network applet.
To change your password by using Novell Client 32, follow this procedure:
FIG. 40.7 With Client 32, you can change multiple NetWare account passwords simultaneously.
After you configure either Microsoft's Service for NDS or Novell's Client 32, you have support for functionality only NDS provides. You can browse NDS trees by using Network Neighborhood, Explorer, and other third-party browsing tools. You can map drives to NDS volumes. You can install printers in the NDS tree. Figure 40.8 shows an example of browsing the tree. Note that you have context-sensitive options when you right-click an object.
FIG. 40.8 When browsing the LVLab OU, you can see the available printers and volumes.
Most NetWare 3.x applications should run under the 32-bit clients provided by Microsoft and Novell. The few that won't are utilities that require support that only the VLM or NETX real-mode clients provide. In most cases, alternative administrative tools are available.
Some NDS applications cannot be used without obtaining the appropriate DLLs from Novell. I recommend using Novell's Client 32 for maximum compatibility if you expect to run NetWare utilities such as NDS Manager or NetWare Administrator for Windows 95. Client 32 is provided with NetWare version 4.x.
File and Print Sharing for NetWare Networks lets your Windows 98 machine look like a NetWare server from a user's perspective. You can map to shares and printers, run some NetWare utilities against it, and assign rights based on users and groups from a real NetWare server.
Setting up user-level access control with NetWare is very similar to setting it up with NT (see the previous section "Logging on to a Windows NT Network" for more details). The following steps show the process.
NOTE: NetWare-based user-level security cannot be used with Novell's Client 32 for accessing files on Windows 98 workstations that are shared with File and Print Sharing for NetWare Networks or for actually sharing the resources on a machine with Client 32 installed.[dagger]
To set up user-level access control for NetWare, follow these steps.
FIG. 40.9 When you install the NetWare client and File and Print Sharing for NetWare networks at the same time, you get this message because the workstation won't be able to connect to a NetWare server until it reboots.
NOTE: If you specify a 4.x server, only the users and groups in the bindery context will be listed and available to assign rights to.[dagger]
Choosing the Browse Method
After File and Print Sharing is installed, you need to choose how your Windows 98 machine will be located, or browsed, by users. You have two options: workgroup advertising or SAP advertising, as shown in Figure 40.10. Table 40.4 gives details on making this selection.
FIG. 40.10 You can choose to have your Windows 98 machine that is acting as a NetWare server browsed using either workgroup advertising or SAP advertising.
| Option | Description |
| Workgroup advertising | Workgroup advertising enables your machine to be browsed by using the standard method any other Windows machine uses to broadcast itself. For example, if all workstations in a workgroup are called ABC, your NetWare server will show up in this workgroup as well. Workgroup advertising is your best option if you're working in an environment with only Windows machines and you don't need to run utilities such as SLIST. It takes up much less bandwidth on a network. You have four settings: Disabled means you're not using this type of advertising; Enabled: May be a Master means that if no other computers are keeping track of the machines in the workgroup, this one will; Enabled: Preferred Master means that this computer will keep track of the machines in the workgroup by default; and Enabled: Will Not Be Master means that this computer will never keep track of the other machines in the workgroup. If this workgroup contains NT machines, you should choose Enabled: Will Not Be Master. |
| SAP advertising | SAP advertising is the native method NetWare servers use to make themselves known on the network. If you are using DOS-based clients or you need to run utilities such as SLIST, SYSCON or others against the Windows 98 machines, use SAP. This protocol is known for being bandwidth intensive, so unless you absolutely need it, workgroup advertising is your better choice. |
Assigning Permissions to Shares and Printers File and Print Sharing for NetWare Networks enables you to assign rights to resources on your workstation, using users and groups that have been created on a real NetWare server. As a result, users have to know the username and password of their account only on the actual NetWare server. When assigning rights, Windows 98 uses two security contexts to enumerate the user and groups from the bindery on the NetWare server. If you're logged on, Windows uses the account with which you're connected to the server to read the bindery information. However, if you're not logged on to the NetWare server, there must be an account called windows_passthru on the server. If the account is missing, Windows 98 does not have the permissions to connect to the server and read the bindery. Instead, you are prompted to log on to the server when you try to assign rights. To assign rights to a folder or printer, right-click on it and choose Sharing (see Figure 40.11).
FIG. 40.11 You need to specify not only the share name for the printer or directory but also who will have what access.
To share a resource, click the Shared As option, assign a Share Name (no spaces), and give the share an optional Comment that will be displayed when a user browses the resources on the machine. Then you need to assign rights to users and groups. For printers, you can grant either Full Access or No Access to users and groups. Folders, however, can have more granular rights. Table 40.5 shows the available rights:
| Option | Description |
| Read Only | A user can list the files in the folder and read them, but cannot make any modifications. |
| Full Access | A user has all possible rights to a folder. This option is not recommended for security reasons. Instead, assign custom rights as needed. |
| Custom | You can selectively choose to assign any combination of the rights shown in Figure 40.12 when you select Custom. Most of the rights are obvious; however, there are a couple of things to clarify. Write to Files doesn't give a user permission to Delete a file, and List Files only allows a user to see what files are there but doesn't allow him or her to read the files. |
CAUTION: The Supervisor account on the NetWare server automatically has full rights to any shares you create on your Windows 98 client using File and Print Sharing for NetWare Networks even if you explicitly specify fewer rights when you assign permissions.
After the resource has been shared, a hand appears under the resource's icon, as shown in Figure 40.13.
FIG. 40.12 The Custom option enables you to assign specific rights.
FIG. 40.13 Windows 98 displays a hand under resources that have been shared.
A significant limitation with File and Print Sharing for NetWare Networks is that you can assign rights to users on only one NetWare server. In other words, if you have server JWSERV and server FINANCE, you can't assign users from both servers rights to your WebSupport share. Another limitation is that you can't have File and Print Sharing for Microsoft Networks and File and Print Sharing for NetWare Networks running on the same machine, because they use totally different protocols. Microsoft Networking uses the SMB protocol, whereas NetWare uses the NCP protocol.
© Copyright, Macmillan Computer Publishing. All rights reserved.