587 lines
24 KiB
HTML
587 lines
24 KiB
HTML
|
|
<!doctype html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
|
<html>
|
|
<head><META http-equiv="Content-Type" content="text/html; charset=utf-8">
|
|
<title>Change NWS User Attributes (CHGNWSUSRA)</title>
|
|
<link rel="stylesheet" type="text/css" href="../rzahg/ic.css">
|
|
</head>
|
|
<body bgcolor="white">
|
|
<script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
|
|
<a name="CHGNWSUSRA.Top_Of_Page"></a>
|
|
<h2>Change NWS User Attributes (CHGNWSUSRA)</h2>
|
|
<table width="100%">
|
|
<tr>
|
|
<td valign="top" align="left"><b>Where allowed to run: </b>All environments (*ALL)<br>
|
|
<b>Threadsafe: </b>No
|
|
</td>
|
|
<td valign="top" align="right">
|
|
<a href="#CHGNWSUSRA.PARAMETERS.TABLE">Parameters</a><br>
|
|
<a href="#CHGNWSUSRA.COMMAND.EXAMPLES">Examples</a><br>
|
|
<a href="#CHGNWSUSRA.ERROR.MESSAGES">Error messages</a></td>
|
|
</tr>
|
|
</table>
|
|
|
|
<div> <a name="CHGNWSUSRA"></a>
|
|
<p>The Change Network Server User Attributes (CHGNWSUSRA) command is used to change network server attributes for an i5/OS user or group profile that operate in a networking environment. This command can be used to do the following:
|
|
</p>
|
|
<ol>
|
|
<li>Set network server attributes for a specific user or group profile. For example, the default NetWare Directory Services Tree name could be set for a specific user profile.
|
|
</li>
|
|
<li>For NetWare networks, the network server attributes can be set up so that this user or group profile will be enrolled into the NetWare network. Where the profile is enrolled depends on the values specified by the NDSTREELST parameter.
|
|
</li>
|
|
<li>For Windows networks, the network server attributes can be set so that a user or group profile will be enrolled into one or more Windows domains or local servers. When enrolling into a Windows local server, the server must be associated with a locally attached Integrated xSeries Server. Where the profile is enrolled depends on the values specified by the WNTDMNLST and WNTLCLSVRL parameters.
|
|
<p>When an i5/OS user is enrolled, a matching Windows user identity is created in the Windows domain or on the Windows local server.
|
|
</p>
|
|
<p>When an i5/OS group profile is enrolled into a Windows domain or local server, a matching Windows group is created in the domain or local server. All i5/OS user profiles that are defined in the group are enrolled into the domain or local server and added to the Windows groups that are currently defined by the user account template.
|
|
</p>
|
|
</li>
|
|
</ol>
|
|
<p>Network server user attributes are saved by the Save System (SAVSYS) and Save Security Data (SAVSECDTA) commands. Network server user attributes are restored to the system when the user profile is restored. The Restore User Profiles (RSTUSRPRF) command can be used to restore user profiles and the network server user attributes associated with them.
|
|
</p>
|
|
<p><b>Restrictions:</b>
|
|
</p>
|
|
<ol>
|
|
<li>Only a user with *OBJMGT and *USE authorities to the user profile being changed, can specify this command.
|
|
</li>
|
|
<li>To make changes to the NDSTREELST, WNTDMNLST, or WNTLCLSVRL parameters, a user must have *SECADM special authority.
|
|
</li>
|
|
<li>The Windows domain and server names specified in the WNTDMNLST and WNTLCLSVRL parameters must follow the naming conventions of Windows.
|
|
</li>
|
|
</ol>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<hr size="2" width="100%">
|
|
|
|
<div>
|
|
<h3><a name="CHGNWSUSRA.PARAMETERS.TABLE">Parameters</a></h3>
|
|
<table border="1" cellpadding="4" cellspacing="0">
|
|
<!-- col1="10" col2="15" col3="30" col4="10" -->
|
|
<tr>
|
|
<th bgcolor="aqua" valign="bottom" align="left">Keyword</th>
|
|
<th bgcolor="aqua" valign="bottom" align="left">Description</th>
|
|
<th bgcolor="aqua" valign="bottom" align="left">Choices</th>
|
|
<th bgcolor="aqua" valign="bottom" align="left">Notes</th>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.USRPRF"><b>USRPRF</b></a></td>
|
|
<td valign="top">User profile</td>
|
|
<td valign="top"><i>Simple name</i>, <b><u>*CURRENT</u></b></td>
|
|
<td valign="top">Optional, Key, Positional 1</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.PRFTYPE"><b>PRFTYPE</b></a></td>
|
|
<td valign="top">Profile type</td>
|
|
<td valign="top"><b><u>*USER</u></b>, *GROUP</td>
|
|
<td valign="top">Optional, Key, Positional 2</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.PMTCTL"><b>PMTCTL</b></a></td>
|
|
<td valign="top">Prompt control</td>
|
|
<td valign="top"><b><u>*ALL</u></b>, *WINDOWS, *NETWARE, *WINDOWSNT</td>
|
|
<td valign="top">Optional, Key, Positional 3</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.PRPGRPMBR"><b>PRPGRPMBR</b></a></td>
|
|
<td valign="top">Propagate group members</td>
|
|
<td valign="top"><b><u>*SAME</u></b>, *NONE, *ALL, *MBRONLY</td>
|
|
<td valign="top">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.DFTSVRTYPE"><b>DFTSVRTYPE</b></a></td>
|
|
<td valign="top">Default server type</td>
|
|
<td valign="top"><b><u>*SAME</u></b>, *WINDOWS, *NWSA, *NETWARE, *WINDOWSNT</td>
|
|
<td valign="top">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.NDSTREE"><b>NDSTREE</b></a></td>
|
|
<td valign="top">NDS tree</td>
|
|
<td valign="top"><i>Character value</i>, <b><u>*SAME</u></b>, *NWSA, *NONE</td>
|
|
<td valign="top">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top"><a href="#CHGNWSUSRA.NDSCTX"><b>NDSCTX</b></a></td>
|
|
<td valign="top">NDS context</td>
|
|
<td valign="top"><i>Path name</i>, <b><u>*SAME</u></b>, *NWSA, *ROOT</td>
|
|
<td valign="top">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top" rowspan="5"><a href="#CHGNWSUSRA.NDSTREELST"><b>NDSTREELST</b></a></td>
|
|
<td valign="top">NDS tree list</td>
|
|
<td valign="top">Single values: <b><u>*SAME</u></b>, *NWSA, *NONE<br>Other values (up to 10 repetitions): <i>Element list</i></td>
|
|
<td valign="top" rowspan="5">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 1: NDS tree</td>
|
|
<td valign="top">
|
|
<i>Character value</i></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 2: User object context</td>
|
|
<td valign="top">
|
|
<i>Path name</i></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 3: Default server</td>
|
|
<td valign="top">
|
|
<i>Character value</i>, <b><u>*ANY</u></b></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 4: Profile object</td>
|
|
<td valign="top">
|
|
<i>Path name</i>, <b><u>*NONE</u></b></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top" rowspan="4"><a href="#CHGNWSUSRA.WNTDMNLST"><b>WNTDMNLST</b></a></td>
|
|
<td valign="top">Windows server domain list</td>
|
|
<td valign="top">Single values: <b><u>*SAME</u></b>, *NWSA, *NONE<br>Other values (up to 64 repetitions): <i>Element list</i></td>
|
|
<td valign="top" rowspan="4">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 1: Domain</td>
|
|
<td valign="top">
|
|
<i>Character value</i></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 2: User template</td>
|
|
<td valign="top">
|
|
<i>Character value</i>, <b><u>*NONE</u></b></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 3: Group type</td>
|
|
<td valign="top">
|
|
<b><u>*GLOBAL</u></b>, *LOCAL</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top" rowspan="3"><a href="#CHGNWSUSRA.WNTLCLSVRL"><b>WNTLCLSVRL</b></a></td>
|
|
<td valign="top">Windows local server list</td>
|
|
<td valign="top">Single values: <b><u>*SAME</u></b>, *NWSA, *NONE<br>Other values (up to 64 repetitions): <i>Element list</i></td>
|
|
<td valign="top" rowspan="3">Optional</td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 1: Server</td>
|
|
<td valign="top">
|
|
<i>Character value</i></td>
|
|
</tr>
|
|
<tr>
|
|
<td valign="top">Element 2: User template</td>
|
|
<td valign="top">
|
|
<i>Character value</i>, <b><u>*NONE</u></b></td>
|
|
</tr>
|
|
</table>
|
|
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
</div>
|
|
<div> <a name="CHGNWSUSRA.USRPRF"></a>
|
|
<h3>User profile (USRPRF)</h3>
|
|
<p>Specifies the name of an i5/OS user profile whose network server attributes are to be set.
|
|
</p>
|
|
<p>The following IBM-supplied objects are not valid on this parameter:
|
|
</p>
|
|
<p>
|
|
<pre>
|
|
QAUTPRF QNFSANON QYCMCIMOM
|
|
QCOLSRV QRJE QEJBSVR
|
|
QDBSHR QSNADS QSRVAGT
|
|
QDBSHRDO QSPL QANZAGENT
|
|
QDFTOWN QSPLJOB QIBMHELP
|
|
QDOC QSYS
|
|
QDSNX QTCP
|
|
QEJB QTFTP
|
|
QFNC QTSTRQS
|
|
QGATE QCLUMGT
|
|
QLPAUTO QTCM
|
|
QLPINSTALL QIPP
|
|
QMSF QPM400
|
|
QNETSPLF QNTP
|
|
QYPSJSVR QCLUSTER
|
|
QNETWARE * QMGTC
|
|
</pre>
|
|
</p>
|
|
<p>* QNETWARE is legal to enroll if it is a user on a NetWare tree or server. Any other use of QNETWARE is not supported.
|
|
</p>
|
|
<p>The following profile names are not valid on this parameter when enrolling to a Windows domain or server.
|
|
</p>
|
|
<p>
|
|
<pre>
|
|
GUEST
|
|
GUESTS
|
|
REPLICATOR
|
|
USERS
|
|
</pre>
|
|
</p>
|
|
<p>Note that QAUTPRF and QNFSANON were not disallowed in versions earlier than V4R1. Also, profiles QPRJOWN, QSRV, QSRVBAS, QSVSM, QTMPLPD, and QUMB were disallowed in pre-V4R1 versions, but are now legal to enroll. The change was made in order to keep in sync with the list of objects that i5/OS security uses for some commands.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*CURRENT</u></b></dt>
|
|
<dd>The user profile attributes for the current user profile are changed.
|
|
</dd>
|
|
<dt><b><i>user-name</i></b></dt>
|
|
<dd>Specify the name of an i5/OS user or group profile.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.PRFTYPE"></a>
|
|
<h3>Profile type (PRFTYPE)</h3>
|
|
<p>Specifies whether the user or group attributes for a profile are to be changed.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*USER</u></b></dt>
|
|
<dd>The user profile attributes are changed.
|
|
</dd>
|
|
<dt><b>*GROUP</b></dt>
|
|
<dd>The group profile attributes are changed.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.PMTCTL"></a>
|
|
<h3>Prompt control (PMTCTL)</h3>
|
|
<p>Specifies which network server attributes should be prompted for on the command.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*ALL</u></b></dt>
|
|
<dd>All parameters are prompted.
|
|
</dd>
|
|
<dt><b>*WINDOWS or *WINDOWSNT</b></dt>
|
|
<dd>Only those parameters that apply to Windows domains and servers are prompted.
|
|
<p>
|
|
<b>Note: </b>*WINDOWS should be used in V5R4 and later releases. The *WINDOWSNT value is supported for compatibility with releases prior to V5R4.
|
|
</p>
|
|
</dd>
|
|
<dt><b>*NETWARE</b></dt>
|
|
<dd>Only those parameters that apply to *NETWARE servers are prompted.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.PRPGRPMBR"></a>
|
|
<h3>Propagate group members (PRPGRPMBR)</h3>
|
|
<p>Specifies how an i5/OS group and its users are to be enrolled. There are two different ways that an i5/OS group and its users can be enrolled.
|
|
</p>
|
|
<ol>
|
|
<li>The i5/OS group is enrolled in the network. All of the members of the group are also enrolled in the network and added to the newly created group.
|
|
</li>
|
|
<li>Only the members of the i5/OS group are enrolled in the network. The group itself is not enrolled in the network.
|
|
</li>
|
|
</ol>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The PRPGRPMBR value does not change. If the PRPGRPMBR parameter has never been set, it is defaulted to *ALL.
|
|
</dd>
|
|
<dt><b>*ALL</b></dt>
|
|
<dd>The i5/OS group and all members of the group are enrolled. Any user profiles added to this group at a later time are also enrolled into the network.
|
|
</dd>
|
|
<dt><b>*MBRONLY</b></dt>
|
|
<dd>Only the members of the group are enrolled. The group itself is not enrolled. Any user profiles added to this group at a later time are also enrolled into the network.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.DFTSVRTYPE"></a>
|
|
<h3>Default server type (DFTSVRTYPE)</h3>
|
|
<p>Specifies the default server type for this user. This attribute is used primarily as a default for those i5/OS commands that support multiple network types.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The default server type does not change.
|
|
</dd>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>The default server type from the system network server attributes is used.
|
|
</dd>
|
|
<dt><b>*WINDOWS or *WINDOWSNT</b></dt>
|
|
<dd>The default server type for the user is set to *WINDOWS.
|
|
<p>
|
|
<b>Note: </b>*WINDOWS should be used in V5R4 and later releases. The *WINDOWSNT value is supported for compatibility with releases prior to V5R4.
|
|
</p>
|
|
</dd>
|
|
<dt><b>*NETWARE</b></dt>
|
|
<dd>The default server type for the user is set to *NETWARE.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.NDSTREE"></a>
|
|
<h3>NDS tree (NDSTREE)</h3>
|
|
<p>Specifies the name of the default NetWare Directory Services tree used by this user. The tree specified should be the one most often used by this i5/OS user when accessing the network.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The NetWare Directory Services tree name does not change.
|
|
</dd>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>The NetWare Directory Services tree specified in the system network server attributes is used.
|
|
</dd>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>No default NetWare Directory Services tree is specified.
|
|
</dd>
|
|
<dt><b><i>'NDS-tree-name'</i></b></dt>
|
|
<dd>Specify the name of the default NetWare Directory Services tree.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.NDSCTX"></a>
|
|
<h3>NDS context (NDSCTX)</h3>
|
|
<p>Specifies the complete path name of a default NetWare Directory Services context, associated with the tree specified by the NDSTREE parameter, to be used when this user issues i5/OS commands that use NDS objects. This becomes the current context when the i5/OS user signs on.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The default NDS context name does not change.
|
|
</dd>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>The NetWare Directory Services context specified in the system network server attributes is used.
|
|
</dd>
|
|
<dt><b>*ROOT</b></dt>
|
|
<dd>The NetWare Directory Services default context is the root of the NDS tree.
|
|
</dd>
|
|
<dt><b><i>'NDS-context'</i></b></dt>
|
|
<dd>Specify the complete path name of the default NDS context name to be used.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.NDSTREELST"></a>
|
|
<h3>NDS tree list (NDSTREELST)</h3>
|
|
<p>Specifies a default list of NetWare Directory Services trees that will be used by the iSeries network administration support to determine which NetWare v4.x trees to enroll this i5/OS profile to. Each entry in the list will contain an NDS tree name and a list of default attributes associated with that tree.
|
|
</p>
|
|
<p>Up to 10 entries can be specified for this parameter. An entry consists of a value from each of the following elements.
|
|
</p>
|
|
<p><b>Single values</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The default NDS tree list entries do not change.
|
|
</dd>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>When *NWSA is specified, the NDS tree list from the network server attributes is used.
|
|
</dd>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>When *NONE is specified, the default is to not enroll this profile to any NetWare v4.x trees.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 1: NDS tree</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><i>'NDS-tree-name'</i></b></dt>
|
|
<dd>Specify the name of the NetWare Directory Services tree where the iSeries network administration support will enroll i5/OS profiles into. The remaining elements describe the network server attributes that are associated with this NDS tree.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 2: User object context</b>
|
|
</p>
|
|
<p>Specifies the location in the NDS tree where newly created NDS user objects are created when enrolling profiles into the NDS tree. If the user object already exits in the NDS tree, it will be moved to this context the first time the iSeries administration support attempts to enroll the i5/OS profile. The NetWare complete name must be specified for this element.
|
|
</p>
|
|
<dl>
|
|
<dt><b><i>'user-object-context'</i></b></dt>
|
|
<dd>Specify the NDS context where profiles will be enrolled into the NDS tree.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 3: Default server</b>
|
|
</p>
|
|
<p>Specifies the default NetWare Directory Services server to be used by the system when enrolling profiles into the NDS tree.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*ANY</u></b></dt>
|
|
<dd>The system selects any active server to use when accessing the NDS tree.
|
|
</dd>
|
|
<dt><b><i>'server-name'</i></b></dt>
|
|
<dd>Specify the name of the default NDS server to be used by the system when enrolling profiles into the NDS tree. If this server is unavailable at the time the request is handled, the system attempts to find an active server that is available to handle the request.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 4: Profile object</b>
|
|
</p>
|
|
<p>Specifies a default NetWare Directory Services profile object that contains the profile login script to be used by the user when logging into the network. The NetWare distinguished name must be specified for this element.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*NONE</u></b></dt>
|
|
<dd>No profile login script is used by the NetWare user.
|
|
</dd>
|
|
<dt><b><i>'profile-object-name'</i></b></dt>
|
|
<dd>Specify the distinguished name of the default NDS profile object containing the profile login script to be used by a user when logging into the network.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.WNTDMNLST"></a>
|
|
<h3>Windows server domain list (WNTDMNLST)</h3>
|
|
<p>Specifies a list of Windows domains that will be used by the i5/OS user enrollment support to determine into which Windows domains this i5/OS profile is enrolled.
|
|
</p>
|
|
<p>Each entry in the list will contain a domain, a user account template name, and a group type. The user account template name is the name of a Windows user identity that is to be used when creating new Windows users.
|
|
</p>
|
|
<p>Up to 64 entries can be specified for this parameter. An entry consists of a value from each of the following elements. A domain name must be entered for each entry and must be unique within the list.
|
|
</p>
|
|
<p>If the WNTDMNLST parameter has never been set, it is defaulted to *NONE.
|
|
</p>
|
|
<p><b>Single values</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The Windows domain list entries do not change.
|
|
</dd>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>When *NWSA is specified, the Windows domain list from the system network server attributes is used.
|
|
</dd>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>When *NONE is specified, this profile will not be enrolled into any Windows domains.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 1: Domain</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><i>'domain-name'</i></b></dt>
|
|
<dd>Specify the name of the Windows domain where the i5/OS user enrollment support will enroll this i5/OS profile.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 2: User template</b>
|
|
</p>
|
|
<p>Specifies the name of a Windows user that can be used as a template when creating new Windows users in the Windows domain.
|
|
</p>
|
|
<p>
|
|
<b>Note: </b>Changing this value will not affect Windows users that are already enrolled in the domain.
|
|
</p>
|
|
<dl>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>No Windows user account template is used when creating a new user identity in the Windows domain.
|
|
</dd>
|
|
<dt><b><i>'user-account-template-name'</i></b></dt>
|
|
<dd>Specifies the name of a Windows user account to be used when creating new Windows user identities in the domain.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 3: Group type</b>
|
|
</p>
|
|
<p>Specifies the type of group to be created in the Windows domain. This element is ignored when PRFTYPE(*USER) is specified.
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*GLOBAL</u></b></dt>
|
|
<dd>A global group is created in the Windows domain.
|
|
</dd>
|
|
<dt><b>*LOCAL</b></dt>
|
|
<dd>A local group is created in the Windows domain.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<div> <a name="CHGNWSUSRA.WNTLCLSVRL"></a>
|
|
<h3>Windows local server list (WNTLCLSVRL)</h3>
|
|
<p>Specifies a list of Windows local servers that will be used by the i5/OS user enrollment support to determine into which Windows local server the i5/OS profile is enrolled. Only those server names associated with locally configured Integrated xSeries Servers can be specified in this list.
|
|
</p>
|
|
<p>Each entry in the list will contain a server name and associated user account template name. The user account template name is the Windows user account to be used when creating new Windows user identities on the server.
|
|
</p>
|
|
<p>Up to 64 entries can be specified for this parameter. An entry consists of a value from each of the following elements. A server name must be entered for each entry and must be unique within the list.
|
|
</p>
|
|
<p>If the WNTLCLSVRL parameter has never been set, it is defaulted to *NONE.
|
|
</p>
|
|
<p><b>Single values</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><u>*SAME</u></b></dt>
|
|
<dd>The value does not change.
|
|
</dd>
|
|
</dl>
|
|
<dl>
|
|
<dt><b>*NWSA</b></dt>
|
|
<dd>When *NWSA is specified, the Windows local server list from the system network server attributes is used.
|
|
</dd>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>When *NONE is specified, this profile will not be enrolled into any Windows local servers.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 1: Server</b>
|
|
</p>
|
|
<dl>
|
|
<dt><b><i>'server-name'</i></b></dt>
|
|
<dd>Specify the name of a Windows local server where the i5/OS user enrollment support will enroll this i5/OS profile. This server must be a locally configured Integrated xSeries Server.
|
|
</dd>
|
|
</dl>
|
|
<p><b>Element 2: User template</b>
|
|
</p>
|
|
<p>Specifies the name of a Windows user that can be used as a template when creating new Windows users on the local server.
|
|
</p>
|
|
<p>
|
|
<b>Note: </b>Changing this value will not affect Windows users that are already enrolled on the server.
|
|
</p>
|
|
<dl>
|
|
<dt><b>*NONE</b></dt>
|
|
<dd>No Windows user account template is used when creating a new user identity on the Windows local server.
|
|
</dd>
|
|
<dt><b><i>'user-account-template-name'</i></b></dt>
|
|
<dd>Specifies the name of a Windows user account to be used when creating new Windows user identities on the local server.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<hr size="2" width="100%">
|
|
<div><h3><a name="CHGNWSUSRA.COMMAND.EXAMPLES">Examples</a> </h3>
|
|
<p><b>Example 1: Enrolling a user into a Windows network</b>
|
|
</p>
|
|
<p>
|
|
<pre>
|
|
CHGNWSUSRA USRPRF(BOB) DFTSVRTYPE(*WINDOWS)
|
|
WNTDMNLST((DMN01 USRTMP1) (DMN02 *NONE))
|
|
WNTLCLSVRL((LCLSVR1 TMPL1) (LCLSRV2 *NONE))
|
|
</pre>
|
|
</p>
|
|
<p>The above command will change the network server user attributes for user profile BOB. BOB's default server type is set to *WINDOWS.
|
|
</p>
|
|
<p>The i5/OS user enrollment support will enroll user BOB into domain DMN01 using user account template USRTMP1 and also into domain DMN02.
|
|
</p>
|
|
<p>The i5/OS user enrollment support will also enroll user BOB into local server LCLSVR1 using user account template TMPL1 and also into local server LCLSRV2.
|
|
</p>
|
|
<p><b>Example 2: Enrolling a user into a NetWare network</b>
|
|
</p>
|
|
<p>
|
|
<pre>
|
|
CHGNWSUSRA USRPRF(DENNIS) NDSTREE(NWTREE1)
|
|
NDSCTX(.MARKETING.HDQTRS.IBM)
|
|
NDSTREELST(*NWSA)
|
|
NTW3SVRLST(NTW3SVR2 NTW3SVR3)
|
|
</pre>
|
|
</p>
|
|
<p>The above command will change the network server user attributes for user profile DENNIS. The default NDS tree will be set to NWTREE1 and the default context to MARKETING.HDQTRS.IBM.
|
|
</p>
|
|
<p>The NDS tree list from the system network server attributes is used. The i5/OS user enrollment support will enroll user DENNIS into each tree specified in the tree list. The NetWare 3.12 server list is set to include servers NTW3SVR2 and NTW3SVR3. User DENNIS will also be enrolled into both of these servers.
|
|
</p>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
<hr size="2" width="100%">
|
|
<div><h3><a name="CHGNWSUSRA.ERROR.MESSAGES">Error messages</a> </h3>
|
|
<p><b><u>*ESCAPE Messages</u></b>
|
|
</p>
|
|
<dl>
|
|
<dt><b>CPFA450</b></dt>
|
|
<dd>Network server user attributes for user profile &1 not changed. See previous messages.
|
|
</dd>
|
|
</dl>
|
|
</div>
|
|
<table width="100%">
|
|
<tr><td align="right"><a href="#CHGNWSUSRA.Top_Of_Page">Top</a></td></tr>
|
|
</table>
|
|
</body>
|
|
</html>
|