Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How to make a replicas on the other domain's domino server

Posted on 2004-09-27
16
Medium Priority
?
1,220 Views
Last Modified: 2013-12-18
Hi experts,

What I want to do is cross-certify two server in different domain's domino, say HK-Domino in HK-Domain and CN-Domino on CN-Domain.

I want make a HK-Domino user mail file replica in CN-Domain and let the HK user can access the mail files in CN-Domino which replicate from HK-Domino.

I read some documents on this site and I know some of the steps but I cannot make the cross-certify successfully. Here are my questions:

1. Should I use cert.id or server.id to make cross-certify ?
2. How to make a safe copy of cert.id or server.id to make the cross-certify ?
3. How to cross-certify the server.id or cert.id ?
4. How to make effect of the cross-certify server.id or cert.id (is it copy to mail directory and restart the domino server?) ?
5. How to identify the server.id or cert.id are cross-certified ?

Many thanks!
0
Comment
Question by:fishwm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
  • 4
16 Comments
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 12167437
It's all described in detail in the Admin Help database. In short, the process involves two servers getting to know each other, whilst you tell them that the other one IS who he claims to be. The idea is to get a safe-id from system A and you cross-certify it on system B, and vice versa. In the process, you don't need to have safe id's, you can do it with the complete id-file. So:

1. You need 2 cert.id files in the process, one for each domain
2. In this case where everything stays internal, don't make safe-id's
3. Use the Admin client and cross-certify the other domain's server.id with this domain's cert.id
4. Nothing needs to be restarted, you need to adapt the ACL of the mailfile or, what's better, you have to adapt either OtherDomainServers or LocalDomainServers groups in the N&A book. It is for you to decide where to put each server. Do check the privileges in the ACL's for the group you put the server in.
5. Have a try...
0
 

Author Comment

by:fishwm
ID: 12167521
Hi Bosman,

Actually, I try it before and I found it was cross-certified under People & Group --> certificates --> Notes Cross Certificates --> HK-Domino--> CN-Domino/CN-Domain

Once I want to create a new replicas in the CN-Domino, it has a error message " 09/28/2004 04:28:58 PM  Admin Process: Received the following error performing a Check Access for New Replica Creation request on HK-Domain's Directory (File name: names.nsf): Server document not found in Domino Directory. "


0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 12167683
The certificate you mention is a certificate for the server only, which could mean that only the server can access the other domain. Are there other people/servers with cross-certificates to that domain? It might be a lot easier to set up domain cross-certification, so your /HK-Domain will accept all from /CN-Domain (and vv).

If you want to see what's wrong and where the error comes from, open the admin4.nsf database on the server and look for the unfinished activities. I suspect the cross-certification is only half completed. Is there also a matching cross-certificate in the other domain's N&A-book?
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 31

Expert Comment

by:qwaletee
ID: 12172878
Sounds like you are properly cross-certified, and just need to get the replicas across... easiest way to check this is to issue a replication command on each servers' console so it tries to replicate with the other server -- on HK-DOmino, issue command REPL CN-Domino/CN-Domain and see if error messages show that it could not conect, or it could connect but could not authenticate (=not cross certified), or successfully replicates, even if there are no actual files to replicate.

The error message you are showing -- server document not found in address book -- is because of a limitation in the Administration process.  It normally can't work across two different domains.  The easy wa around this is to not use the amdin process to create the replicas -- just open a database using the regular Notes client, File -> Replication -> New Replica, and target the new rpelica to the other server.

You CAN get the admin process to work this way.  Go to Administration Help, click on Index, and go to the CROSS-SOMAIN ADMINISTRATION REQUESTS topic.
0
 

Author Comment

by:fishwm
ID: 12186450
Ho qwaletee,

I try to repliacte with cn-domino in CN-Domain, a lot of message come out :

09/30/2004 10:24:47 AM  Access control is set in CN-Domino/CN-Domain mailjrn.nt
f to not allow replication from mailjrn.ntf
09/30/2004 10:24:47 AM  Finished replication with serverCN-Domino/CN-Domain
09/30/2004 10:24:47 AM  Database Replicator shutdown

It seems can replicate with the CN-Domino but the access control block to the replication. I try to add the access right on server document : server --> current server document --> security --> create new replicas to otherDomainServer

and
server --> current server document --> security --> create database and templates to otherDomainServer

Should I using otherDomainServer ? I cannot found the HK-Domino in the address book!


0
 

Author Comment

by:fishwm
ID: 12186624
I just means how to set the access right in CN-Domino let HK-Domino to create replicas on CN-Domino.
0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 12188832
Did you add the servers' names to the groups I mentioned?
0
 

Author Comment

by:fishwm
ID: 12198411
Hi bosman,

U mean add the server in the OtherDomainServers or LocalDomainServers groups ? But the server did not appear in the address book, how can I add the server in these group?

0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 12198857
Type the name in the group, it doesn't have to be in the N&A-book. You need to give it permission somehow. Either you put the full name in the ACL, or you use the always-present OtherDomainServers or LocalDomainServers group documents.
0
 

Author Comment

by:fishwm
ID: 12205758
Hi bosman,

After I add the server document and I can select the object of HK-Domino in the address book. So I try to make a replicas of a mail file to the CN-Domino.

A admin request was created but a message come out:

"10/02/2004 10:36:06 AM  Admin Process: Received the following error performing a
 Accelerated Create Replica request on Teddy Cheng (File name: admin4.nsf; Name:
 HK-Domino/HK-Domain): The destination server is not configured to be sent this type"

and the replica did not appear in the CN-Domino !

Any thing I missed ?
0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 12206392
Why did you start with a mialfile? For starters, try the N&A-book itself. The N&A-books should be replicated from one domain to the other, to facilitate mail (using Directory Assistance).

> After I add the server document ...
Add a Server document?? Where? There should be NO Server document of a server outside a domain in the N&A-book!

If you didn't add the CN-server's name to the HK-server's Local or OtherDomainServer, then that is what you missed in the first place. I'm sorry to say that I'm no AdminP specialist, so I cannot really place the message you supplied.

How and where did you try to create the replica? Do you yourself have access to the servers, permission to create replicas, and permission to Manage the mailfile?
0
 
LVL 31

Accepted Solution

by:
qwaletee earned 300 total points
ID: 12702348
My fault... I did not follow up at the end.  fishwm misunderstood a message about FILE access levels, and assumed it was a SERVER access issue.  Therefore he pursued it as "I need the other server to grant my server acess to create replicas."  Wrong... the replica was already created, but the replica file did not explcitly list his server as having access to do updates.

At the same time, that means his original question (how to create replicas) was ni fact resolved, but there was a follow on problem.  So, I'll take the points :)
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 12702721
Fishwm, did you just close this question?  Thanks.  I hope your problem is fully resolved.
0
 

Author Comment

by:fishwm
ID: 12703826
Not fully resolved but you help me a lot on this problem. Thx!
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 12710418
This should be easy to resolve.  Please give an update status, either in this questino or by opening another.  Honestly, I think you should open another.
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For beginners of Lotus Notes user this is important to know about the types of files and their location supported by IBM Notes. Mostly users are unaware about how many file types are created and what their usages are. This Article is fully dedicated…
Article by: Rob
Notes 8.5 Archiving Steps and Tips This article covers setting up a Notes archive, and helps understand some of the menu choices making setting up and maintaining a Notes archive file easier.
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question