Solved

Login to Active Directory first, then eDirectory, without prompt for 2nd login

Posted on 2007-11-13
9
1,701 Views
Last Modified: 2012-08-14
I would like to login using the Microsoft GINA first, and have the username and password passed to the Novell GINA so that the user doesn't get prompted to log in a second time (provided their passwords are in sync). (My ultimate goal is to get group policy and printers from Active Directory, and login to eDirectory to get access to the Zenworks Application Launcher.)

I have tried setting the GinaDLL to be MSGINA.DLL, and that is insufficient. The "Login without Novell's GINA" setting gets rid of the second login prompt, but doesn't authenticate the user to eDirectory.

What settings are necessary to accomplish this?
0
Comment
Question by:dlcarraw
  • 3
  • 2
  • 2
9 Comments
 
LVL 29

Expert Comment

by:matrixnz
ID: 20275906
Hi dlcarraw

Heres an article on how to install Zenworks for Desktops in a Windows Environment

Installing ZfD 4.x in a Windows-Only Environment
http://www.novell.com/documentation/zdpr/index.html?page=/documentation/lg/zdpr/zdprinst/data/aliq069.html

With Novell you could setup Dynamic Local Users which basically synchronised the Novel System with the Windows Local Account, when using Zenworks separately, you basically don't require edirectory.

Hope that made sense.

Cheers
0
 
LVL 35

Accepted Solution

by:
ShineOn earned 250 total points
ID: 20276537
matrixnz, I don't see how that answers his question.  

You can't use DLU with Windows AD group policy.  The two are immiscible.  If you succeed in having both active, results will always be unpredictable at best.

dlcarraw, you don't need to use the msgina in order to have Windows group policy take effect.  You can get Windows group policy and still have the NWGINA primary.  Pretty-much all you need is to join your computers to the AD domain and make sure no ZEN group-policy packages are active for anyone, by disabling the workstation manager.  That won't disable the application launcher, just the ZEN policy management.  The user can log in to the AD domain seamlessly from the NWGINA and even process AD login scripts.
0
 
LVL 29

Expert Comment

by:matrixnz
ID: 20276786
Hi ShineOn

My last point was just pointing out how Novell worked if you checked the link above, it refers to implimenting Zenworks in an Windows/AD environment, from dlcarraw initial post he's wanting to use Zenworks for Application Deployment very much like SMS etc..  

Also I should clarify, "you basically don't require edirectory." I was referring to Novell edirectory.

Cheers
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 35

Expert Comment

by:ShineOn
ID: 20277046
ZEN needs eDirectory through version 7.  ZENworks Configuration Management 10 can run in an AD-only environment.  
0
 
LVL 1

Author Comment

by:dlcarraw
ID: 20487828
A little more detail.
I want to use Active Directory for all group policy - this will enable me to install software and printers, etc as we migrate away from Novell. I want to simultaneously use the Zenworks Application Launcher because we have hundreds of application objects in eDirectory, so I don't want to have to move all of those to Active Directory at once.

I've had the MSGINA thing work a few times, so I know it's possible, I just don't know how to make it repeatable.
0
 
LVL 1

Author Comment

by:dlcarraw
ID: 21670632
While I appreciate the comments, the solutions offered were for me to use Novell's ZENWorks, rather than accomplish the goal of making MSGINA the primary login with the NW client installed. This was not the question and did not meet my needs.

The latest Novell client has support for using non-NWGINAs. I have had that work, though not with contextless login (another story). So the solution is to use Novell's native support in newer versions of the NW client.
0
 
LVL 35

Expert Comment

by:ShineOn
ID: 21671934
I disagree.  My first comment (20276537) gave a complete, clear, clean and simple answer to the question.  

You wanted to log in to both AD and eDirectory, use AD for policies and use ZENworks for app deployment.  The simplest and easiest to accomplish method for that was my comment.

MSGINA is stupid - it only cares about MS stuff.  To authenticate to eDirectory subsequent to MSGINA you need to force a resource to be used that's known to be provided by eDirectory, which will force the login to eDirectory to occur.  It's not "seamless" like it is if you use NWGINA as primary.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Ok I have been working on this for some time having learned and gained certification in XenDesktop 4 along came version 5 which was released last month. Since then I have been working to deploy XenDesktop 5 in a small environment with only 2 virt…
Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now