A.1 Installation and Upgrade Issues

A.1.1 Over-the-Wire Upgrade (OTWUG) Requirements

You must have iChain 2.3 SP1 or later to complete the OTWUG.

A.1.2 OTWUG vs. CD Upgrade

The CD upgrade provides large DOS and Sys volume sizes. The advantage of the CD upgrade are the ability to save core dumps out to the DOS volume for debugging.

A.1.3 Upgrading From iChain 2.2 to iChain 2.3

When upgrading from iChain 2.2 to iChain 2.3, you are prompted with the EULA. This is a one-way process and you must confirm it in order to continue. If you are upgrading from iChain 2.2, enable telneton.nas from the GUI. It is disabled by default.

IMPORTANT:You cannot upgrade from iChain 2.2 to iChain 2.3 SP3 using the OTWUG. You must upgrade to iChain 2.3 SP1 or SP2 first.

A.1.4 OTWUG Might Have to Use IP Addresses

If a DNS services is not available, the OTWUG must use IP addresses.

A.1.5 Additional RADIUS Configuration Required

With the added functionality in iChain 2.3 of being able to combine RADIUS authentication with LDAP authentication, additional configuration is needed to map the RADIUS user common name to a distinguished name in the LDAP authentication tree.

The recommended way to do this is to create an LDAP authentication profile named ldaprad to be used to find the distinguished name of the user in the LDAP authentication tree. See the Novell iChain 2.3 Administration Guide online for details.

To do this using the aclcheck profile, as done in previous versions of iChain, the ldap logintype of the aclcheck profile needs to be modified, as well as the ldap searchbase and ldap bindanonymous settings.

Set the ldap logintype to FieldName using the following command on the iChain server command line interface:

set authentication aclcheck ldap logintype = FieldName

A.1.6 Importing a .NAS File, Changing to the Factory Settings Can Cause a Reboot

The default settings for SNMP have changed to:

set snmp monitor=no
set snmp name=iChain

These settings changes can cause a server reboot if you import a .nas file from a previous version or change to the factory settings.

A.1.7 Password Management Information Lost When Importing .NAS File

If you import an iChain 2.2 .nas file that contains password management servlet information to an iChain 2.3 server, the password information might be lost because the SNMP files change. If this occurs, you need to reboot. Importing iChain 2.3 .nas files with the same information works properly.

A.1.8 The Servlet Directory Has Been Removed in iChain 2.3

The servlet directory is no longer available in iChain 2.3. This includes the java, class, and jar files related to the servlets that were previously available on the iChain Authorization CD. To access these servlets, see the Novell Cool Solutions Web site.

A.1.9 Accessing the SecretStore Client Utilities

For the iChain 2.3 release, the SecretStore client utilities have been removed from the authorization server CD. To get the latest version of these utilities, go to the Novell NDK Web site.