If you are a Domino Administrator you know the answer to this question:
Can your Domino server start without the names.nsf file being found?
Of course not.
Yet, clients always try to prove you wrong.
A support ticket came in and it said the address book had gone AWOL. When i logged in to the network and check on the server, it was up and running. Scratching my head, I spoke to the customer and they ended up sending me a screenshot showing quite clearly how in the Admin client, the names.nsf was not visible from the left column where it usually would appear.
I pointed out that the view in the admin client is based on the Directory assistance and LDAP databases. If those are not running or configured you will not see them, but they are definitely there. (Yes, I had checked the physical files were there too) oddly enough I could not find much in searching online to explain it, so anyone with more in depth knowledge, feel free to comment and I will update this post accordingly.
It turns out LDAP had been loaded on the server manually, not via the notes.ini so at some restart they "lost" the files.
Edited notes.ini and loaded LDAP to bring everything back to normal.
The customer was adamant the server was down, yet they could tell, just like I could, that the server was up and running fine. An issue of education, or a case of change is not good which throws them off their game?
While it is our job to support and help the customers, we should also be taking the time to explain to them what is going on, how to resolve it, and why it happened. When we know.
I admit when there are just some things we don't know and the time involved to find out may not be equitable to clients. This was not one of those times, but we all run into the crazy exceptions that happen.
One can never be bored supporting customers, that is for sure.
Showing posts with label LDAP. Show all posts
Showing posts with label LDAP. Show all posts
Tuesday, September 22, 2015
Thursday, June 20, 2013
IBM Connections 4.5 Installation Details Spreadsheet
Last year around this time I posted what became a top 10 page for my blog, the IBM Connections 4.0 installation spreadsheet. I took the IBM Wiki page provided and broke it down by topics (IHS, WAS, DB2, etc) and included some items along the way as well.
For those that need, that is, should be, documenting your installation details, hopefully this helps make your life easier.
Yesterday IBM posted an update for 4.5 CR1 here.
I have updated my spreadsheet and included the changes as posted as well.
You can get the new version and make sure it says 45 in the title here or from my Downloads page.
Enjoy
For those that need, that is, should be, documenting your installation details, hopefully this helps make your life easier.
Yesterday IBM posted an update for 4.5 CR1 here.
I have updated my spreadsheet and included the changes as posted as well.
You can get the new version and make sure it says 45 in the title here or from my Downloads page.
Enjoy
Tags:
#ibm,
ccm,
db2,
details,
filenet,
ibm,
ibm_connections,
IHS,
keith_brooks,
LDAP,
spreadsheet,
TDI,
websphere
Thursday, August 25, 2011
2,670 Attempts in 11 minutes
Hackers still trying to break in using LDAP on one of our web facing Domino Servers.
If you do not use DDM on your public side servers, you may be missing hackers attempts.
This was from 2:30 am EST to 2:41am EST an average of 243 attempts per minute or 4 a second.
My phone was not happy for a little while as DDM sends me alarms for security failed login attempts.
Maybe there should be a LDAP attempt block lockout, like user logins get blocked if they fail to login properlyh after x number of times.
If you think so, go vote at Ideajam, someone posted this over 2 years ago!
If you do not use DDM on your public side servers, you may be missing hackers attempts.
This was from 2:30 am EST to 2:41am EST an average of 243 attempts per minute or 4 a second.
My phone was not happy for a little while as DDM sends me alarms for security failed login attempts.
Maybe there should be a LDAP attempt block lockout, like user logins get blocked if they fail to login properlyh after x number of times.
If you think so, go vote at Ideajam, someone posted this over 2 years ago!
Expanding Domino Web Lockout feature to work with LDAP
Tags:
hackers and spammers,
LDAP
Friday, March 6, 2009
I got, you got, she's got, he's got
MUTEX. CreateMutex too and the perennial MVP CglobalMutex.
Yes, it's true, you may have this too, but only if you have an old version of Symantec Mail Security for Domino (SMSDOM.exe).
Imagine my surprise when setting up an LDAPsearch test with a client and see this error:
Now I know BES has the discombobulator and Domino has its own funny messages, but never hit this one until today.
Quick search of the IBM toolbar shows only 2 references, this and that technotes. The latter one is related to an LEI error of the same nature.
This says:
WAIT! That's not what we were doing at all, but it explains a lot, server is 7.0.1 What's interesting is we were running ldapsearch of course locally and in a command prompt. Maybe I should let support know this message needs to include these options.
They basically tell you to go here(syamntec's technote) which of course says:
So go get an updated version.
Client decided they don't need it anymore and anyway they have the new version just never installed it. They are going to Barracuda, thus the LDAP call.
I am never amazed at the excellent coding error messages displayed from vendors.
Yes, it's true, you may have this too, but only if you have an old version of Symantec Mail Security for Domino (SMSDOM.exe).
Imagine my surprise when setting up an LDAPsearch test with a client and see this error:
SMSDOM Panic: CreateMutex failed in CGlobalMutex constructor
[Windows Err Num: 5 (0x5): Access is denied.]
Now I know BES has the discombobulator and Domino has its own funny messages, but never hit this one until today.
Quick search of the IBM toolbar shows only 2 references, this and that technotes. The latter one is related to an LEI error of the same nature.
This says:
This issue with terminal service is fixed in Domino 6.5.6 and 7.0.2 levels. If running at levels below, issue the command locally on the server.
WAIT! That's not what we were doing at all, but it explains a lot, server is 7.0.1 What's interesting is we were running ldapsearch of course locally and in a command prompt. Maybe I should let support know this message needs to include these options.
They basically tell you to go here(syamntec's technote) which of course says:
To mitigate the problem, install update your version of Symantec Mail Security for Domino.
The Symantec Mail Security for Domino extension manager must load Nnem.dll in the same instance of NNTASK for proper operation.
So go get an updated version.
Client decided they don't need it anymore and anyway they have the new version just never installed it. They are going to Barracuda, thus the LDAP call.
I am never amazed at the excellent coding error messages displayed from vendors.
Friday, February 27, 2009
ST-SNTT Embedded Awareness of 8.5 clients
Late update before I split to go grilling tonight.
Received a call from my partner that he can not get awareness to work in his inbox since going to the 8.5 Lotus notes client and Sametime 8.0.2 which he is using on the embedded side.
I use the connect client so hadn't tested this recently.
Sure enough it didn't work.
Updated the Sametime.ini with any version of client code(list is here) not listed yet that I know we use, just in case.
Logged in again, still no change.
Now go find the option above in the picture under the community you are trying to log in from the preferences.
In our case we run an LDAP canonical login so swap the two and all worked again.
Now can someone please tell me why I can login to ibmext from my Vista laptop using 801 ST connect but can not from my XP using the same version(or 802 as I just updated it).
Enjoy, time to go home and grill.
Wednesday, January 21, 2009
LDAP Stands for...
A piece from my speedgeeking which I forgot to post.
LDAP = Last Domino Administrator's Problem
And who's is it today? YOURS
And who's might it be tomorrow? MINE
LDAP = Last Domino Administrator's Problem
And who's is it today? YOURS
And who's might it be tomorrow? MINE
Thursday, January 8, 2009
ST-SNTT LDAP and DA, Forgot about this Issue
When are support people right but wrong?
When you only look at one side of an equation.
We have a Lotus Sametime server which started having problems the day after new years.
Error messages like this: Problems uploading this graphic for some reason, never mind just yanked it out of the log file.
Something must have gone bad, right? Well we had some DNS issues left over from the data center move so who knows what was relevant, right?
I tried updating the Sametime Server to 8.0.2, didn't fix it.
Updated Domino to 8.0.2, still no changes.
Then on the 6th 8.5 came out, yes, updated it to 8.5IF1 (yes a fix was out the same day). Still error messages but Sametime works now. ST Logger and ST Community still fail. hmmm.
Also got this message on the LDAP server:
So updated the LDAP server to 8.5If1 too. As an aside it took 40 minutes! 32 or so to back it up, 7 or so to install it. Got to love Domino. Try that with an Exchange Server!
Was informed this error message is because the Directory Assistance (DA) database on the LDAP server should NOT have the LDAP server referenced. Meaning you need to have one DA.nsf on the LDAP server which does not replicate to all other servers and they in turn need a DA.nsf with LDAP in it.
Confused? so was I. IBM Support is still working on the ST Logger issue.
The moral of the story is if you don't tell your tech guy/team/support person on the phone everything about your environment you may end up hurting yourself more. Luckily I am not new to this and almost created more havoc had I just disabled the LDAP reference in the DA.
When you only look at one side of an equation.
We have a Lotus Sametime server which started having problems the day after new years.
Error messages like this: Problems uploading this graphic for some reason, never mind just yanked it out of the log file.
01/02/2009 12:19:44 PM HTTP JVM:
-----Servlet Information-----
Servlet name: scs
Servlet class: com.lotus.sametime.configuration.DominoConfigurationServlet
Servlet state:
Configuration parameters: ServletURL=scs
Info for: com.lotus.sametime.configuration.DominoConfigurationServlet@34903490
01/02/2009 12:19:44 PM HTTP JVM: javax.servlet.ServletException: Unable to get configuration object: Exception while generating Server List: Database open failed (%1): Unable to get configuration object: Exception while generating Server List: Database open failed (%1)
Something must have gone bad, right? Well we had some DNS issues left over from the data center move so who knows what was relevant, right?
I tried updating the Sametime Server to 8.0.2, didn't fix it.
Updated Domino to 8.0.2, still no changes.
Then on the 6th 8.5 came out, yes, updated it to 8.5IF1 (yes a fix was out the same day). Still error messages but Sametime works now. ST Logger and ST Community still fail. hmmm.
Also got this message on the LDAP server:
01/07/2009 11:22:57 AM Error attempting to access the Directory *ILove.lotusphere.COM:389 (no available alternatives), error is LDAP
Server is NOT available.
So updated the LDAP server to 8.5If1 too. As an aside it took 40 minutes! 32 or so to back it up, 7 or so to install it. Got to love Domino. Try that with an Exchange Server!
Was informed this error message is because the Directory Assistance (DA) database on the LDAP server should NOT have the LDAP server referenced. Meaning you need to have one DA.nsf on the LDAP server which does not replicate to all other servers and they in turn need a DA.nsf with LDAP in it.
Confused? so was I. IBM Support is still working on the ST Logger issue.
The moral of the story is if you don't tell your tech guy/team/support person on the phone everything about your environment you may end up hurting yourself more. Luckily I am not new to this and almost created more havoc had I just disabled the LDAP reference in the DA.
Thursday, November 20, 2008
QSnTT - When an Error Message Gets Misplaced

Sometimes one gets away from you. This must be Quickr's for R8.1.
I received this after converting a Quickr server from using LDAP as it's Directory to Domino as it's Directory.
I am using a browser, yet the error believes me to be using a Notes Client. Has Lotus taken over Firefox? Has Firefox embedded a Notes Client in itself?
Remember to revert any changes in the qpconfig.xml for LDAP when doing this.
Evidently there are some hard coded references to LDAP or Domino Directory in the Main.nsf that must get touched (or reinstalled). Anyone who's done this let me know, Stuart and I have similar issue doing the exact reverse processes. He is going to LDAP from Domino Directory.
UPDATED 30 minutes later: My problem was a looping caused by 2 references in the DA file and removing the 2nd NAB from the Quickr server. So we are back on LDAP, now to fix port 636 to be open at the firewall for SSL LDAP. Never a dull minute.
Tags:
directory,
Domino,
error,
LDAP,
Lotus Quickr
Thursday, November 6, 2008
Q-SnTT - DA Configuration Reminder

When involved in the Quickr world, at times(ok, almost all the time) you may want to connect external people to your server.
How do you do it?
Create a Directory Assistance database (Ctrl+N, select the server and advanced templates to find it). Name it da.nsf.
In the DA document select LDAP if you need to include an external LDAP server or Notes for internal Directory Catalogs (DirCat) or Extended Directories.
Fill in the blanks. It is fairly obvious what to fill in where....EXCEPT for
the field called Domain, which is NOT asking for your Lotus Domain.
Name it anything else and then save it and you are good to go.
Why is this? I don't know, but it is.
On the tab marked rules(the middle tab usually) select trusted for credentials and say YES.
On the LDAP tab, if you selected it, if you are not using SSL make sure to select the proper options, otherwise you will not find your LDAP server.
Caveat, AD (Active Directory) requires a Base DN to be used, o=companyname most likely)
If you selected Notes instead of LDAP on this tab you would put any of the other Domino directories you will be using, no need to include the names.nsf itself, it searches that by default.
And don't forget to mark it Enabled.
Next save it all.
Then add the da.nsf to your server document on the basics tab.
Now go to a server console and type "Show X R" without the quotes.
You should see names.nsf first then your LDAP server.
Any problems, you know how to find me.
Subscribe to:
Posts (Atom)