20 Novell Domain Services for Windows Best Practices Guide
docsys (en) 14 November 2013
3.3 Existing DNS Server
Bydefault,theDSfWinstallationconfiguresaDNSserverintheforestrootdomainʹsfirstdomain
controller,andintroducesanewDNSLocatorobjectinthetree.Ifyouhavealreadyconfigured
NovellDNSServerinthesametree,usingtheexistingDNSLocatorobjectismandatory.Youcando
thisbyprovidingtheexistingDNSLocatorcontextinYaSTduringDSfWConfiguration.Thiswill
ensurethatifDSfWisconfiguredtoserveanexistingdomain,theexistingDNSZoneisextended
withDSfW‐specificDNSsettingsinsteadofcreatingaduplicateDNSZone.
Inanexistingenvironment,specifythe
existingDNSLocatorobject.Otherwise,anewDNSLocator
Objectwillbecreatedwithanewzoneforthesamedomainname.Thisnewduplicatezonewillneed
tobemanuallymergedintotheexistingDNSZoneusingNovellDNS/DHCPConsole.Atreecan
containmultipleDNSLocators.However,werecommend
thatyouhaveauniqueDNSLoca torobject
pertree.ThisensuresthattherearenoduplicateDNSZonesinthetreeanditenablesthezonestobe
managedintheDNS/DHCPconsole.
WerecommendthatyoucreatetheDNSentriesforthenewDSfWserversbeforeinstallingDSfW.
ThisisbecauseserverscanresolveeachotherusingthenameandIPaddresswheninstallingDSfW
intoanexistingtree.IftherearenewDNSzonescreatedfortheDSfWdomains ,youshouldcreate
thesezonesbeforetheDSfWinstallation.IfexistingDNSZonesarereused,ensurethattheDSfW
DNSserverservingthedomainissetasDesignatedPrimaryforthezonesafterdeployingthe
domaincontrollers.Thisisapplicableforallforwardandreversezones.
3.4 Linux User Management
Followtheguidelinesgivenbelow:
PlacetheUnixConfigurationObject(UCO)intheupperlayersofthetreeinaseparatecontainer
(forexample,
ou=LUM,o=services
)andmaintainasingleUCOpertree.Foranyadditional
serverinstallationinthesametree,ensurethattheexistingUCOisutilizedduringLUM
configurationinYaST.
CleanuptheexistingPOSIXattributesonuserandgroupobjectsbeforedeployingtheDSfW
domain.ThePOSIXattributesincludeallthe
attributesthatbelongtotheLUMschema
extensions,suchas
uidNumber, gidNumber, homeDirectory, loginShell
.
IfyouhavemodifiedthedefaultPOSIXIDranges,ensurethattheydonotclashwiththeDSfW
IDranges.TheLUMdefaultUIDandGIDnumberfortheDSfWdomainrangesfrom0to65500.
3.5 Domain Controller on Hypervisor
Consideracautiousapproachwhenplacingthedomaincontrollerinavirtualizedenvironmentsuch
asVMware,Citrix,orMicrosofthypervisor.Followtheguidelinesgivenbelow:
Ensurethatyousecurethehostcomputerwherethevirtualdomaincontrollerishostedand
protectitfrommalicioususers.
Protectthedomaincontrollerʹs
virtualharddiskfiles(forexamplethe.vmdfiles).Ensurethat
onlyreliableadministratorshaveaccesstothedomaincontrollerʹsVHDfiles.
Directoryoperationsarecriticallytime‐dependent.Ensurethatthedomaincontrollerand
hypervisorhosttimeisalwayssynchronizedwiththesamereliableNTPtimesourceandtoa
sourcethatisoutsidethehypervisor.VMinfrastructurescancause serioustimedrifts.
Separatethevirtualizationinternaltrafficfromtheguesttraffic.