Tag: guide

  • The IT Department Survival Guide for New Starters

    Welcome to IT.

    You have been recruited because the organisation believes you possess valuable technical skills, sound judgement and the ability to remain calm under pressure.

    Within three weeks you will discover that your actual role is to explain why a printer cannot be fixed by changing somebody’s password.

    This guide exists to help.

    1. Learn the First Law of IT

    Everything is your fault.

    The payroll system is slow.

    IT.

    The meeting room is cold.

    IT.

    A customer cannot remember their username.

    IT.

    The coffee machine says DESCALE.

    IT.

    Karen has deleted an Excel workbook containing the organisation’s entire procurement strategy.

    Definitely IT.

    You may occasionally attempt to explain that Information Technology does not control plumbing, building access, furniture, catering or the weather.

    This is a beginner’s mistake.

    The user does not care which department owns the problem.

    They have found somebody wearing a headset.

    That somebody is you.

    Accept this.

    It will save time.

    2. Never Say “That Should Work”

    The gods hear this.

    You may test a system for six months.

    You may perform penetration testing, regression testing, failover testing, disaster recovery testing and a full dress rehearsal involving nineteen engineers and a conference bridge.

    The moment you tell management:

    “That should work.”

    A certificate will expire.

    Prefer:

    “We have not identified any current impediment to successful operation.”

    This means the same thing but allows considerably more room for professional retreat.

    Other useful phrases include:

    “That’s interesting.”

    Meaning:

    That is absolutely fucked.

    “I haven’t seen that before.”

    Meaning:

    I have seen this six times and none ended well.

    “Let me check the logs.”

    Meaning:

    Please stop talking while I think.

    “There may be a dependency.”

    Meaning:

    Nobody documented this bastard thing.

    “We need to understand the business impact.”

    Meaning:

    Is anyone actually using it?

    3. The Service Desk Knows Everything

    Treat the Service Desk well.

    Senior architects may understand strategy.

    Network engineers may understand routing.

    Security may understand certificates.

    Database administrators may understand things spoken of only in whispers.

    But the Service Desk knows that Finance cannot print on Thursdays because Derek installed a label printer driver in 2019.

    This is real knowledge.

    The CMDB will tell you:

    FIN-PRINT-04 — HP LaserJet — ACTIVE

    The Service Desk will tell you:

    “That’s actually the tea-room printer. FIN-PRINT-04 fell down the stairs during the office move. The one Finance uses is called Susan.”

    Believe the Service Desk.

    Buy them biscuits.

    4. Do Not Insult Legacy Systems

    You will encounter systems older than some employees.

    Do not laugh.

    A Windows Server 2008 machine under someone’s desk may turn out to process £80 million a year in direct debits.

    An Access 2003 database called:

    MASTER_FINAL_USE_THIS_ONE_v7.mdb

    may contain the only authoritative record of something legally significant.

    A beige PC in Facilities may control every door in the building.

    You will ask:

    “Why hasn’t this been replaced?”

    Everyone will look at the floor.

    You will eventually learn that replacement was proposed in:

    and 2024.

    Each programme produced a strategy.

    The old system continued running.

    Do not mock it.

    It has survived more transformation programmes than you have.

    Show respect.

    5. Never Reboot Anything Without Witnesses

    Rebooting a laptop is harmless.

    Rebooting a server is theology.

    Before restarting infrastructure, obtain:

    a ticket,

    an approved change,

    a backup,

    a rollback plan,

    a witness,

    and preferably a small priest.

    The application owner will insist that the system can be restarted at any time.

    Do not believe them.

    The moment it goes down, seventeen unidentified business processes will emerge screaming from the darkness.

    One of them will be “month end.”

    It is always month end.

    Nobody knows when month end begins.

    It appears to last approximately thirty-one days.

    6. Production Is Different

    Development works.

    Test mostly works.

    Pre-production is theoretically identical to production.

    It is not.

    Production contains:

    three undocumented firewall rules,

    a certificate installed by somebody who left in 2018,

    a manual DNS entry,

    a service account called temp_admin,

    and one scheduled task created by Keith.

    Never delete Keith’s scheduled task.

    Nobody knows what it does.

    Keith is unreachable.

    But whenever the task is disabled, Belgium stops invoicing.

    7. Learn the Hierarchy of Passwords

    There are passwords.

    There are admin passwords.

    There are service accounts.

    There are break-glass accounts.

    There are credentials stored in approved privileged-access systems.

    And there is a text file called:

    passwords.txt

    on an old shared drive.

    Security will insist this does not exist.

    Operations will know exactly where it is.

    Your objective is not to become comfortable with this.

    Your objective is to survive long enough to remove it without bringing down payroll.

    8. DNS Is Probably Involved

    When an application behaves inexplicably, someone will eventually say:

    “Could be DNS.”

    This will be offered as either wisdom or sarcasm.

    Do not dismiss it.

    DNS has caused enough damage to earn its reputation.

    Other usual suspects include:

    certificates,

    time synchronisation,

    firewalls,

    proxies,

    permissions,

    storage,

    load balancers,

    and that one forgotten NAT rule in the disaster recovery site.

    Eventually somebody will discover the actual cause was a typo.

    This does not invalidate the investigation.

    It merely completes it.

    9. Certificates Expire Only on Weekends

    Certificate expiry dates are visible months in advance.

    Monitoring systems can alert on them.

    Renewal processes can be automated.

    Owners can be assigned.

    None of this matters.

    The certificate will expire at 02:13 on a Sunday.

    A senior manager will call.

    They will say:

    “The website is down.”

    You will ask:

    “Which website?”

    They will reply:

    “The website.”

    This is all the information you are getting.

    10. Change Management Is a Ritual, Not a Guarantee

    The change form exists to answer several important questions:

    What are you changing?

    Why?

    When?

    How?

    What happens if it goes wrong?

    Who approved this madness?

    You will spend forty minutes completing it.

    The Change Advisory Board will spend four minutes discussing it.

    Someone will ask:

    “Has the business approved this?”

    You will say:

    “Yes.”

    Someone else will ask:

    “What’s the rollback?”

    You will repeat the paragraph already on screen.

    The change will be approved.

    Then, two hours before implementation, an executive will request an “urgent small amendment.”

    The small amendment will fundamentally alter the architecture.

    You will be asked whether it can be included under the existing change.

    It cannot.

    It will be.

    11. Incidents Have Gravity

    A Priority 4 incident is ignored.

    A Priority 3 gets a ticket.

    A Priority 2 gets a Teams call.

    A Priority 1 bends spacetime.

    People who have never previously shown interest in the system will materialise.

    Directors will join the bridge.

    Suppliers will join.

    Cyber will join.

    Communications will join.

    Someone from Risk will ask whether the incident is “contained.”

    Nobody knows what that means yet.

    The technical team will be trying to fix the problem while twenty-three people ask them for updates.

    Eventually somebody sensible will create two calls:

    Technical Bridge.

    Management Bridge.

    This is one of civilisation’s greatest inventions.

    On the Management Bridge, executives can ask:

    “When will it be fixed?”

    On the Technical Bridge, engineers can answer:

    “When you stop fucking asking.”

    12. Never Give a Recovery Time Unless You Mean It

    Management will request an ETA.

    They do not actually want an estimate.

    They want certainty disguised as an estimate.

    If you say:

    “Thirty minutes.”

    At twenty-nine minutes someone will ask:

    “Are we still on track?”

    At thirty-one minutes your estimate will be treated as a failed contractual commitment.

    Prefer:

    “We are working through the recovery sequence. I’ll update when we have a validated restoration point.”

    This is IT language for:

    We have no bloody idea, but Gary has found something promising.

    13. Gary Is Important

    Every department has a Gary.

    Gary may not actually be called Gary.

    He may be called Steve, Anita, Mo, Raj, Susan or Dave.

    Gary has worked there for twenty-seven years.

    Gary knows:

    why server names begin with Z,

    which fibre pair is actually live,

    why Warehouse Three must never be rebooted remotely,

    which database column is lying,

    and why the chief executive’s laptop cannot be replaced before the board meeting.

    Gary’s knowledge is undocumented because nobody has ever given Gary enough time to document it.

    Management describes this as a key-person risk.

    Then gives Gary more work.

    Identify Gary.

    Protect Gary.

    Learn from Gary.

    If Gary says:

    “Don’t touch that.”

    Do not touch that.

    14. Architecture Diagrams Are Historical Fiction

    The diagram you receive on your first day will contain:

    two firewalls,

    three servers,

    a database,

    and a cloud.

    The actual environment will contain:

    six firewalls,

    forty-seven servers,

    three clouds,

    a forgotten MPLS circuit,

    two appliances nobody owns,

    and something labelled “temporary gateway” installed eleven years ago.

    Treat architecture diagrams as archaeological evidence.

    Useful.

    Interesting.

    Not necessarily current.

    If somebody says:

    “The diagram is accurate.”

    Ask:

    “As of when?”

    This question will make you unpopular but powerful.

    15. The CMDB Is Aspirational

    Configuration Management Databases contain valuable information about assets, dependencies and ownership.

    In theory.

    In practice, you may find:

    three entries for the same server,

    an application owner who retired,

    a laptop listed as a critical production dependency,

    and a database marked “decommissioned” which is currently processing customer transactions.

    Never assume the CMDB is wrong.

    Never assume it is right.

    Think of it as a witness with a complicated relationship with truth.

    16. The Cloud Is Someone Else’s Computer, Plus Billing

    At some point someone will say:

    “We should move this to the cloud.”

    This may be correct.

    It may also mean:

    We would like the same mess, but billed monthly.

    Cloud platforms provide extraordinary capabilities.

    They also allow an enthusiastic developer to create £18,000 of infrastructure before lunch.

    Learn tagging.

    Learn budgets.

    Learn identity.

    Learn networking.

    Learn how egress charging works before somebody creates an exciting multi-cloud architecture.

    Most importantly, never accept the phrase:

    “It’ll be cheaper.”

    Ask:

    “Compared with what?”

    Watch the room become philosophical.

    17. Vendors Are Your Friends Until Renewal

    Suppliers will use phrases such as:

    strategic partnership,

    customer success,

    digital journey,

    co-innovation,

    and trusted advisor.

    These expressions mean:

    We would like another purchase order.

    A vendor account manager will remember your birthday if the contract is large enough.

    Three months before renewal, they will become intensely interested in your roadmap.

    One month after renewal, support will ask you to reproduce the problem on the latest version.

    The latest version will not support your operating system.

    This is enterprise software.

    18. Licensing Is Dark Magic

    Nobody fully understands enterprise licensing.

    Not Sales.

    Not Procurement.

    Not Legal.

    Not the vendor.

    Certainly not the auditor.

    You will encounter concepts such as:

    named user,

    concurrent user,

    processor,

    core,

    socket,

    virtual core,

    installed instance,

    running instance,

    minimum quantities,

    indirect access,

    multiplexing,

    and “authorised environment.”

    At some point you will ask:

    “How many licences do we actually need?”

    The room will go quiet.

    A consultant will be hired.

    Three months later you will receive a spreadsheet containing thirty-seven tabs and the phrase:

    Subject to contractual interpretation.

    Keep it.

    It cost £90,000.

    19. Security Will Say No

    This is partly their job.

    Do not become angry.

    Instead ask:

    “What control objective are we trying to satisfy?”

    This transforms an argument into architecture.

    Sometimes.

    Security may still say no.

    If they do, ask for the requirement in writing.

    Not because you intend to fight them.

    Because six months later somebody will ask why the project is late.

    Documentation is not bureaucracy.

    Documentation is armour.

    20. Users Lie, But Usually Innocently

    “The computer just deleted my file.”

    No, it didn’t.

    “I haven’t changed anything.”

    They have.

    “It worked yesterday.”

    Possibly.

    “I’ve restarted it.”

    They logged off.

    “The internet is down.”

    One website is unavailable.

    “My password definitely works.”

    It does not.

    Do not accuse users of lying.

    Users report their model of reality.

    Your job is to identify the gap between their model and the logs.

    Be polite.

    You may need these people later.

    Especially Payroll.

    Never antagonise Payroll.

    21. Screenshots Are Evidence

    Ask for a screenshot.

    Not:

    “What did the error say?”

    Users will paraphrase:

    “It said access or something.”

    The actual message will say:

    SQLSTATE 28000: Login failed for user svc_finance_prod.

    This distinction matters.

    Screenshots also reveal:

    the URL,

    time,

    username,

    browser,

    environment,

    and seventeen browser tabs containing information you did not ask to know.

    Be professional.

    22. Never Trust “Quick Question”

    A colleague approaching your desk with:

    “Quick question…”

    is carrying at least forty-five minutes of work.

    Common variants include:

    “Can I pick your brain?”

    “Just while you’re here…”

    “You know about networks, right?”

    “This’ll only take a second.”

    The correct response is not hostility.

    The correct response is:

    “Sure. What’s the ticket number?”

    Watch nature take its course.

    23. Projects End. Applications Do Not.

    Projects have budgets.

    Governance.

    Steering committees.

    Milestones.

    Celebrations.

    Applications have Tuesday mornings.

    The project team will deliver a shiny new system.

    Photographs will be taken.

    Cake may appear.

    Then the project closes.

    Six months later Operations asks:

    “Who supports this?”

    Silence.

    The project manager has moved to another transformation programme.

    The architect is consulting in Dubai.

    The supplier says support was not included.

    The business says IT owns it.

    IT says the business owns it.

    The application continues running.

    This is how legacy begins.

    24. Backups Are Not the Same as Recovery

    Someone will proudly tell you:

    “We back everything up.”

    Ask:

    “Have we restored it?”

    A backup that has never been restored is a theory.

    A disaster recovery plan that has never been tested is literature.

    A failover process dependent on one person remembering a password is folklore.

    Test recovery.

    Document recovery.

    Then test the document.

    Otherwise, during an incident, somebody will discover that the backup server depends on the system you are trying to restore.

    This is called enterprise architecture.

    25. Monitoring Produces Two States

    No alerts.

    Too many alerts.

    In the first state, management asks whether monitoring works.

    In the second, everyone ignores it.

    Your mission is to reach the mythical third state:

    Useful alerts.

    This involves deleting hundreds of alarms that effectively mean:

    “CPU exists.”

    If every event is critical, nothing is critical.

    This principle also applies to email marked HIGH IMPORTANCE.

    26. Meetings Reproduce

    IT meetings reproduce by mitosis.

    A project meeting identifies a technical issue.

    A technical meeting is created.

    The technical meeting identifies a security concern.

    A security workshop is created.

    The security workshop identifies a dependency.

    A dependency call is created.

    Eventually eight people attend meetings all day discussing work none of them now has time to perform.

    Protect blocks of actual working time.

    Do not apologise for this.

    Someone has to configure the thing.

    27. Teams Status Is Political

    Green means available.

    Yellow means possibly alive.

    Red means either extremely busy or eating lunch.

    Do Not Disturb means senior architect attempting to produce something before another meeting begins.

    Offline means nothing.

    Some people have been “Offline” since 2022 while responding instantly to every message.

    Do not infer reality from Teams presence.

    It is less reliable than the CMDB.

    28. Document Everything Important

    Especially decisions.

    After a meeting, write:

    “To confirm our agreed position…”

    This sentence has prevented more professional disasters than most cybersecurity products.

    Record:

    what was decided,

    who decided it,

    what assumptions were made,

    what risks were accepted,

    and who owns the next action.

    Six months later, when someone says:

    “IT recommended this architecture.”

    You can produce the email showing that IT recommended the opposite.

    Do not wave it triumphantly.

    Simply attach it.

    The effect is stronger.

    29. Never Become the Only Person Who Knows

    Being indispensable feels good.

    Until you want a holiday.

    Document your work.

    Cross-train colleagues.

    Share passwords through proper systems.

    Automate repetitive tasks.

    The goal is not to become the hero who receives calls at 03:00.

    The goal is to build systems that do not require heroes.

    Heroic IT is usually failed engineering wearing a cape.

    30. Finally: Find the People Who Actually Make Things Work

    Every IT department has formal structures.

    Architecture.

    Infrastructure.

    Applications.

    Service Management.

    Security.

    PMO.

    Data.

    Cloud.

    Workplace.

    Networks.

    Then there is the real structure.

    The network engineer who answers the phone.

    The DBA who knows the ancient application.

    The Service Desk analyst who notices patterns.

    The project manager who writes things down.

    The security architect who explains rather than obstructs.

    The desktop engineer who knows the executives.

    The developer who admits when something is broken.

    The procurement person who understands the licence.

    The administrator who knows where the contract lives.

    Find these people.

    Be useful to them.

    Do not waste their time.

    Share credit.

    Bring biscuits occasionally.

    And remember the final rule.

    One day, perhaps years from now, a nervous new starter will approach your desk.

    They will say:

    “Sorry, quick question. Everyone says you know how this works.”

    You will look at the undocumented system.

    You will look at the obsolete server.

    You will remember Gary.

    Then you will hear yourself say:

    “Right. Whatever you do, don’t reboot it.”

    And at that moment, your induction will finally be complete.

  • Novell NetWare

    Architecture, Administration, Operations, and Migration

    NetWare 3.12 through 6.5 SP8  |  Bindery, NDS/eDirectory, TFS, NSS, IPX, and native IP

    Version 1.0  |  8 August 2026

    For legacy operations, recovery, technical archaeology, and controlled migration

    Contents

    Select an entry in Word or a compatible viewer to jump to that section. Major sections begin on a new page for field use.

    How to use this reference

    Scope and conventions

    Support and security status

    Version families at a glance

    Compatibility questions to ask first

    Architecture and operating model

    The NetWare mental model

    Bindery versus NDS and eDirectory

    Core services stack

    Boot, configuration, and runtime

    Boot sequence

    NCF configuration files

    Safe boot and recovery switches

    NLMs and protected address spaces

    Networking and service discovery

    IPX and SPX environments

    Native IP and SLP environments

    Core ports and flows

    Client-to-file-service flow

    NDS and eDirectory administration

    Tree structure and naming

    Partitions, replicas, and replica rings

    Bindery emulation

    Time synchronization and directory health

    Directory administration tools

    Rights and security model

    File system trustee rights

    eDirectory object and property rights

    Effective rights and inherited rights filters

    Practical rights patterns

    File and directory attributes

    Storage, volumes, and file systems

    Traditional file system versus NSS

    NSS storage hierarchy

    Namespaces and path compatibility

    Salvage, purge, quotas, and capacity

    Repair boundaries

    Clients, drive mappings, and login scripts

    Client families

    Path syntax and mappings

    Login script execution order

    Login script example

    Administration quick reference

    Primary administration tools

    Console command quick reference

    Workstation utility quick reference

    Core NLM quick reference

    Illustrative NCF skeletons

    Operations runbook

    Daily, weekly, and monthly checks

    Controlled maintenance shutdown

    Change preparation checklist

    Troubleshooting playbooks

    Server will not start or SYS will not mount

    Clients cannot find a server

    Authentication or login script failure

    Access denied or files are invisible

    Slow response or high utilization

    Volume or pool is full

    Abend or repeated restart

    eDirectory synchronization errors

    Backup and disaster recovery

    What a usable backup must preserve

    Recovery rehearsal

    Printing and ancillary services

    Printing generations

    Other common services

    Containment, preservation, and migration

    Minimum containment pattern

    Migration sequence

    Virtualization and historical preservation

    Appendix A – Common paths and files

    Appendix B – Glossary

    Appendix C – Official source set

    How to use this reference   Back to contents

    This is a practical reference for engineers who must understand, recover, operate, or retire a Novell NetWare environment. It is not a replacement for the manual matching the exact server version, support pack, hardware driver set, eDirectory build, and installed applications.

    WORKING ASSUMPTION: The operational detail is centered on NetWare 4.x through 6.5, while NetWare 3.12 and Bindery behavior are called out where they differ. Commands marked as examples must be validated on the target server before use.

    Scope and conventions   Back to contents

    1. Server-console commands appear in uppercase for readability; NetWare commands are generally not case-sensitive.
    2. A path such as SYS:SYSTEM identifies a volume and directory. A path such as SERVER/SYS:PUBLIC also identifies the server.
    3. NDS refers to Novell Directory Services; later documentation uses eDirectory. In this guide, NDS/eDirectory means the directory service family.
    4. TFS means the NetWare Traditional File System. NSS means Novell Storage Services.
    5. Source markers such as [S2] refer to the official source set in Appendix C.

    Support and security status   Back to contents

    NetWare 6.5 SP8 is the terminal NetWare release line. It entered extended support in 2010, and the vendor’s later Premium Lifeline offering ended on 31 December 2016. It must therefore be treated as unsupported legacy infrastructure in 2026. [S1, S13]

    SECURITY BOUNDARY: Do not expose NCP, SLP, IPX routing, Telnet, RConsoleJ, legacy web administration, LDAP, or old TLS endpoints directly to the Internet or to an untrusted enterprise segment. Place the server behind an allow-list firewall on an isolated VLAN and administer it through a controlled jump host or modern encrypted tunnel.

    • Use unique legacy credentials; do not reuse current privileged passwords.
    • Disable services and protocols that are not required, particularly Telnet, IPX, anonymous LDAP, and legacy web components.
    • Keep ALLOW UNENCRYPTED PASSWORDS set to OFF unless a documented, temporary compatibility exception exists. [S2]
    • Assume that old cryptographic implementations and browser-based interfaces do not meet modern security baselines.
    • Capture configuration and recovery media before every change because replacement drivers, patches, and vendor support are scarce.

    Version families at a glance   Back to contents

    Version family summary

    FamilyDirectory modelNetwork emphasisOperational significance
    2.xPer-server BinderyIPX/SPXDedicated 286-era file server; highly version- and hardware-specific.
    3.x / 3.12Per-server BinderyIPX/SPX with SAP/RIP32-bit 386 line; NLM model; mature departmental file and print platform.
    4.x / intraNetWareNDS tree plus Bindery emulationIPX/SPX; IP add-onsIntroduced global directory, partitions, replicas, and directory-based administration.
    5.0 / 5.1NDSNative IP plus optional IPXNCP became transport-independent; SLP and NSS became central; multiprocessor and memory model advanced. [S14]
    6.0eDirectoryIP preferred; IPX optionalExpanded web access, iPrint/iFolder era services, and user-oriented licensing.
    6.5 / SP8eDirectory 8.7.3 or 8.8.xIP preferred; IPX retainedFinal mature NetWare line. New SP8 installs used eDirectory 8.8.4; updated systems could retain 8.7.3. [S1]
    OES / Enterprise ServereDirectory on LinuxIPSuccessor platform providing NCP, NSS, trustee semantics, CIFS, iPrint, and migration paths without the NetWare kernel. [S12]

    Compatibility questions to ask first   Back to contents

    1. What exact NetWare version, support pack, eDirectory version, JVM, and application build are installed?
    2. Is the server Bindery-only, NDS/eDirectory-native, or serving legacy clients through Bindery emulation?
    3. Are clients using IPX, native IP, or both? Which Ethernet frame types and SLP scopes are in use?
    4. Are volumes Traditional or NSS? Which namespaces, trustee assignments, quotas, compression, encryption, and salvage policies exist?
    5. Does the server hold directory partitions or replicas, and is it a Master replica, time source, SLP Directory Agent, Organizational CA host, licensing host, or cluster node?
    6. Which third-party NLMs, backup agents, database engines, and hardware-specific .HAM, .CDM, .LAN, and .PSM drivers are required?
    7. Are licenses, installation media, overlay media, support packs, driver disks, and keys preserved and legally usable?

    Architecture and operating model   Back to contents

    The NetWare mental model   Back to contents

    NetWare is a network services operating system, not a general-purpose desktop Unix or Windows server. The kernel is optimized around file, print, directory, protocol, and application services. Administrators interact with a server console and loadable modules; users interact through NCP clients, mappings, login scripts, and directory objects.

    Logical layers

    LayerExamplesRole
    ClientsDOS requester, VLM, Client32, Novell Client, NetStorageAuthenticate, discover services, map paths, consume file/print services.
    DirectoryBindery or NDS/eDirectoryStores identities, groups, servers, volumes, policies, schema, and service objects.
    Application/file serviceNCP, queue print, NDPS/iPrint, GroupWise, BtrievePresents network resources and application services.
    Discovery and transportSAP/RIP over IPX; SLP over IP; TCP/UDPLocates services and carries NCP or application traffic.
    File systemTraditional volumes or NSS pools and volumesStores data, trustees, attributes, quotas, namespaces, and salvage metadata.
    RuntimeSERVER.EXE, NLMs, protected address spacesExecutes kernel services, drivers, protocol stacks, and server applications.
    Hardware interfacePSM, HAM, CDM, LAN drivers, NWPAConnects processors, storage, and network adapters to the runtime.

    KEY DISTINCTION: An eDirectory Volume object represents a volume in the directory, but file access is governed by trustee metadata stored in the file system. Directory rights and file-system rights are related administration domains, not interchangeable ACLs. [S8]

    Bindery versus NDS and eDirectory   Back to contents

    Directory model comparison

    CharacteristicBinderyNDS/eDirectory
    ScopeOne database per serverDistributed tree spanning servers and sites
    NamingFlat object names on a selected serverHierarchical distinguished names in containers
    AdministrationRepeat users/groups on each serverCreate identities and policies once in the tree
    ResilienceServer-local backup and recoveryPartitions and replicas provide distributed availability
    Legacy supportNative to 2.x/3.x4.x+ can expose selected containers as a Bindery context
    Authentication targetServerTree and context, with a server used to reach a replica

    Core services stack   Back to contents

    1. NCP provides file-service semantics, connection management, locking, trustee enforcement, and related client services.
    2. NDS/eDirectory provides identities, objects, schema, authentication, partitions, and replication.
    3. NSS provides a journaling file system, storage pools, volumes, trustee metadata, salvage, quotas, compression, and optional encryption.
    4. IPX/SPX with SAP/RIP supplies legacy transport and discovery; TCP/IP with SLP supplies the later native-IP equivalent.
    5. NLMs extend the kernel with drivers, protocol stacks, management tools, backup agents, and server applications.

    Boot, configuration, and runtime   Back to contents

    Boot sequence   Back to contents

    1. The machine firmware starts the boot device and the small DOS boot environment used by classic NetWare installations.
    2. AUTOEXEC.BAT normally changes to C:\NWSERVER and invokes SERVER.EXE.
    3. SERVER.EXE reads STARTUP.NCF from the boot directory, applies pre-mount SET parameters, and loads platform and storage drivers.
    4. The server discovers storage and mounts SYS. If SYS cannot mount, SYS:SYSTEM modules and AUTOEXEC.NCF are unavailable.
    5. SYS:SYSTEM\AUTOEXEC.NCF executes, setting the server identity and loading LAN drivers, protocols, directory services, logging, and installed applications.
    6. Additional service-specific NCF files are called in their configured order. Users and clients can then discover and connect to the server.

    RECOVERY PRINCIPLE: Separate pre-SYS failures from post-SYS failures. STARTUP.NCF, platform support, and storage drivers dominate the first class. AUTOEXEC.NCF, network bindings, directory services, and application NLMs dominate the second.

    NCF configuration files   Back to contents

    Important NCF files

    FileNormal locationPurpose
    STARTUP.NCFC:\NWSERVERPre-SYS parameters plus platform and storage driver load order.
    AUTOEXEC.NCFSYS:SYSTEMServer identity, network drivers/bindings, services, and application start order.
    SHUTDOWN.NCFSYS:SYSTEMOptional orderly unload or stop commands run by DOWN or restart. [S2]
    SECURE.NCFConfigured locationOptional commands executed through the secure-start mechanism.
    Application .NCFUsually SYS:SYSTEM or application pathStarts or stops a product-specific set of NLMs.
    • Use EDIT or NWCONFIG to change NCF files, and retain a dated known-good copy before editing.
    • Place CONLOG near the beginning of AUTOEXEC.NCF if early console messages are needed; the default log is SYS:ETC\CONSOLE.LOG. [S2]
    • Only persist a SET parameter after confirming whether it belongs in STARTUP.NCF or AUTOEXEC.NCF. The SET display identifies valid locations. [S2]
    • Do not reorder storage, directory, or application modules without documenting dependencies.

    Safe boot and recovery switches   Back to contents

    SERVER and restart switches

    InvocationEffectUse
    SERVER -NSSkips STARTUP.NCFDiagnose a bad pre-mount parameter or driver line; storage may need loading manually.
    SERVER -NASkips AUTOEXEC.NCFMount SYS but prevent post-mount services and applications from starting.
    SERVER -S filename.NCFUses an alternate startup fileBoot a controlled known-good driver set. [S1, S2]
    RESTART SERVER -NSRestarts without STARTUP.NCFRepeat controlled pre-mount diagnosis.
    RESTART SERVER -NARestarts without AUTOEXEC.NCFRepeat controlled post-mount diagnosis.

    BEFORE REPAIR: Photograph or capture the console, preserve BOOT$LOG.ERR, CONSOLE.LOG, ABEND.LOG, STARTUP.NCF, AUTOEXEC.NCF, driver versions, and disk layout. Do not begin with VREPAIR, REBUILD, or DSREPAIR repair operations merely because the server failed to boot.

    NLMs and protected address spaces   Back to contents

    LOAD links an NLM or driver into the operating system; UNLOAD releases it and returns resources. Many server utilities can be loaded when needed, while LAN, storage, directory, and protocol modules form persistent dependencies. MODULES lists loaded modules and their address spaces. [S2, S3]

    1. Kernel address space provides maximum integration but a faulty NLM can abend the server.
    2. Protected address spaces run suitable applications in ring 3. PROTECT filename.NCF loads the modules from an NCF into a named protected space.
    3. PROTECTION lists protected spaces and can enable restart behavior. Drivers, SERVER.EXE, and some core modules cannot run protected.
    4. Unload dependent modules in reverse order. Never force-kill an address space until the data-integrity and vendor implications are understood.

    Networking and service discovery   Back to contents

    IPX and SPX environments   Back to contents

    Legacy IPX/SPX components

    ComponentFunctionDiagnostic focus
    IPXConnectionless routed network protocolNetwork numbers, frame types, bindings, routes
    SPXConnection-oriented transport over IPXSessions, sequence/retry behavior, compatible stack
    SAPAdvertises server and service namesDISPLAY SERVERS; hop count; filtering
    RIP/NLSPRoutes IPX networksDISPLAY NETWORKS; duplicate network numbers; convergence
    NCP/IPXCarries NetWare file and service requestsNCPIPX.NLM, connection state, packet loss
    ODIClient LAN driver and protocol interfaceLSL, NIC driver, frame type, IPXODI/VLM order

    Common Ethernet frame types include ETHERNET_802.2, ETHERNET_II, ETHERNET_802.3, and ETHERNET_SNAP. A client and server can share the physical Ethernet while remaining logically invisible if frame type or external network numbers do not match.

    IPX DISPLAY CAVEAT: DISPLAY SERVERS and DISPLAY NETWORKS show SAP/RIP information. They are not native-IP service-discovery commands; use SLP and TCP/IP tools for IP-only systems. [S2]

    Native IP and SLP environments   Back to contents

    NetWare 5 made NCP transport-independent and introduced a practical pure-IP deployment model. NCP over TCP/UDP uses native IP, while Service Location Protocol (SLP) replaces much of the name-to-address discovery previously supplied by SAP. [S3, S14]

    1. SLP User Agents issue queries, Server Agents register services, and Directory Agents provide a repository for registrations.
    2. Named SLP scopes partition discovery information. A server or client that queries the wrong scope can appear unable to find an otherwise healthy service.
    3. SLP uses TCP and UDP port 427. NCP over IP uses port 524. [S14]
    4. SYS:ETC\SLP.CFG can define static Directory Agents with DA IPV4 entries; DHCP options 78 and 79 can also supply agents and scopes.
    5. Directory replication can be affected when NDAP and Bindery service entries are absent from the scopes used by replica servers.

    Core ports and flows   Back to contents

    Common TCP/UDP ports – verify against the installed service configuration

    PortProtocol/serviceOperational note
    524 TCP/UDPNCP over IP / eDirectory service accessPrimary Novell client and server service path.
    427 TCP/UDPSLPService queries, registrations, and Directory Agent traffic.
    389 TCPLDAPDirectory access; clear-text unless protected externally or upgraded to TLS.
    636 TCPLDAPSDirectory access over legacy TLS; validate certificate and cipher compatibility.
    123 UDPNTPTime synchronization when XNTPD/NTP is selected.
    53 TCP/UDPDNSName service when DNS is hosted or consumed.
    80/443 TCPApache, iManager, NetStorage, iPrint or application web servicesActual bindings vary by installed pattern and reverse proxy design.
    8008/8009 TCPNovell Remote Manager, commonlyVersion/configuration dependent; never expose to an untrusted segment.
    413 TCPSMDR, commonlyStorage Management Services remote backup communication. [S3]
    2034-2036 TCPRConsoleJ agent/proxy variantsHistorical remote console ports; firewall-only and version dependent. [S2]

    FIREWALL RULE METHOD: Inventory listening modules and configured bindings on the actual server, capture a known-good traffic trace, then allow only required source/destination pairs. Do not use a generic ‘NetWare ports’ rule set as an exposure baseline.

    Client-to-file-service flow   Back to contents

    1. The client obtains a server or tree target from a preferred server, preferred tree, explicit name, SLP, SAP, DNS, or cached configuration.
    2. The client resolves the service to an IP or IPX address and opens an NCP connection.
    3. The user authenticates to the Bindery server or to NDS/eDirectory through a server holding or locating the required replica.
    4. Container, profile, and user login scripts execute and create drive/search mappings.
    5. NCP evaluates trustee rights, IRFs, security equivalence, file attributes, locks, quotas, and namespace rules for each operation.

    NDS and eDirectory administration   Back to contents

    Tree structure and naming   Back to contents

    Common eDirectory objects

    ObjectPurposeTypical relationship
    [Root]Top of one directory treeContains top-level organizations and holds the root partition.
    O / OrganizationTop-level administrative containerOften represents the enterprise.
    OU / Organizational UnitDelegation and policy containerOften represents geography, function, or service domain.
    UserIdentity and login propertiesMember of groups; may have home directory and login script.
    GroupSecurity equivalence and shared assignmentUsed for file trustees and application roles.
    ServerRepresents a serverAssociated with volumes, addresses, services, and directory replicas.
    VolumeDirectory representation of a volumePoints users and tools to file storage; data rights remain in the file system.
    ProfileReusable login scriptAssigned to users between container and user scripts.
    Alias / Directory MapAlternate object name or path abstractionReduces path coupling and supports user-friendly mappings.

    Typed name:     CN=PJONES.OU=ARCHITECTURE.O=ACME
    Typeless name:  PJONES.ARCHITECTURE.ACME
    Absolute name:  .PJONES.ARCHITECTURE.ACME
    Relative name:  PJONES   (when the current context is ARCHITECTURE.ACME)

    Dot notation is written from the leaf toward [Root]. LDAP notation normally reverses the order and separates components with commas, for example CN=PJONES,OU=ARCHITECTURE,O=ACME.

    Partitions, replicas, and replica rings   Back to contents

    • A partition is a contiguous subtree stored and replicated as a unit.
    • The Master replica coordinates partition operations. Read/Write replicas accept updates; Read-Only replicas serve reads; Subordinate Reference replicas preserve connectivity across partition boundaries.
    • All servers holding a replica of a partition form its replica ring. A healthy ring exchanges changes and agrees on partition and replica metadata.
    • Partitions improve scale and locality; replicas improve availability. Excessive partitioning or poorly placed replicas increase synchronization and WAN complexity.
    • The first servers in a new tree normally receive root-partition replicas; later placement should be planned around site availability and directory dependencies. [S7]

    MASTER IS NOT PRIMARY: Ordinary object writes can occur on writable replicas. The Master is special for partition and replica operations; it is not a single writable directory server in the Active Directory PDC sense.

    Bindery emulation   Back to contents

    NetWare 4.x and later can present selected NDS/eDirectory containers to Bindery-aware clients and applications. The BINDERY CONTEXT SET parameter identifies up to 16 containers, separated by semicolons, whose objects are exposed through Bindery services. [S2]

    SET BINDERY CONTEXT = OU=SALES.O=ACME;OU=ACCOUNTING.O=ACME

    1. The specified containers must be available on the server through local directory replicas or references.
    2. Bindery-aware applications see a flat view and can encounter duplicate short names across contexts.
    3. Changing the Bindery context is a compatibility change; test authentication, print, backup, and application dependencies.

    Time synchronization and directory health   Back to contents

    Directory operations depend on coherent timestamps. Official health procedures call for time checks, replica synchronization checks, schema checks, and review of obituaries and directory versions. A dynamic tree should be checked about weekly; a static tree about monthly, and every tree before a major directory operation. [S10]

    LOAD DSREPAIR
      Time Synchronization
      Report Synchronization Status

    SET DSTRACE=ON
    SET DSTRACE=NODEBUG
    SET DSTRACE=+S
    SET DSTRACE=*H
      Expected healthy indicator: All Processed = Yes
    SET DSTRACE=NODEBUG
    SET DSTRACE=OFF

    DO NOT REPAIR BY REFLEX: DSREPAIR is both a diagnostic and a repair tool. Start with time, version, replica, and synchronization reports. Preserve a supported directory backup and understand the replica ring before initiating destructive or topology-changing repair options.

    Directory administration tools   Back to contents

    Directory tool map

    ToolBest useCaution
    NWAdminClassic Windows NDS object administrationSnap-ins and behavior are version specific.
    ConsoleOneCross-platform objects, schema, rights, and product snap-insJava/runtime dependencies can be fragile.
    iManagerBrowser-based role and task administrationOld TLS and plug-ins require isolation and compatible browser/runtime.
    iMonitorDirectory health, partitions, replicas, agents, tracesDiagnostic visibility can expose sensitive directory data.
    DSREPAIRTime, replica, database, and synchronization diagnostics/repairUse health reports first; repairs can alter directory state.
    DSTRACELive directory process and synchronization traceFilters can be noisy; capture to file and disable when finished.

    Rights and security model   Back to contents

    File system trustee rights   Back to contents

    File and directory trustee rights

    CodeRightMeaning
    SSupervisorAll file-system rights; cannot be blocked by an IRF.
    RReadOpen and read files.
    WWriteModify file contents.
    CCreateCreate files/subdirectories; supports salvage semantics where applicable.
    EEraseDelete files and directories.
    MModifyRename items and change file or directory attributes.
    FFile ScanSee and search names in the file-system structure.
    AAccess ControlAdd/remove trustees and change trustee rights and IRFs.

    The workstation RIGHTS utility displays or changes assignments. ALL grants all rights except Supervisor. A plus adds rights, a minus removes rights, and a rights list without plus/minus replaces the assignment. [S2]

    RIGHTS SYS:DATA R W C E M F /NAME=.TEAM_ARCHITECTURE.ACME
    RIGHTS SYS:DATA /NAME=.PJONES.ARCHITECTURE.ACME /I
    RIGHTS SYS:DATA /T
    RIGHTS SYS:DATA REM /NAME=.OLDGROUP.ACME

    eDirectory object and property rights   Back to contents

    eDirectory rights

    ClassRightMeaning
    ObjectSupervisorAll rights to the object and its properties.
    ObjectBrowseSee the object; does not reveal its property values.
    ObjectCreateCreate objects beneath a container; includes Browse.
    ObjectDeleteDelete the target object.
    ObjectRenameChange the target object’s name.
    PropertySupervisorComplete control over the selected property.
    PropertyCompareTest a value without reading it.
    PropertyReadRead property values; includes Compare.
    PropertyWriteCreate, change, or delete property values.
    PropertyAdd SelfAdd/remove the trustee itself in object-valued properties such as group membership.

    SENSITIVE DELEGATION: Broad Read access to all User attributes can expose password-management attributes in some eDirectory configurations. Delegate only the object and property rights required for the task. [S8]

    Effective rights and inherited rights filters   Back to contents

    Effective rights are the rights available at the moment of access after NetWare/eDirectory combines explicit trustee assignments, group membership, security equivalence, inherited assignments, and the applicable IRFs. [S8]

    1. An IRF removes selected rights as they flow down a directory or file-system hierarchy.
    2. A lower explicit trustee assignment can add required rights back at the target level.
    3. File-system Supervisor cannot be filtered by a file-system IRF; assign it sparingly.
    4. An apparent rights failure can instead be a visibility failure: File Scan is required to see names, and Read is required to open content.
    5. Check the user’s direct assignment, group assignments, security equivalences, IRFs along the path, the target’s explicit assignment, and file attributes.

    Practical rights patterns   Back to contents

    Common assignment patterns

    Use caseSuggested trustee patternNotes
    Home directoryUser: R W C E M F; administrator group: SSet at each home root or through automated provisioning; protect parent visibility.
    Shared read-only dataReader group: R FRead alone is insufficient for useful browsing; File Scan exposes names.
    Shared working areaContributor group: R W C E M FExclude Access Control unless users must delegate rights.
    Drop boxPurpose-built rights and visibility designTest create, read-back, overwrite, rename, delete, and listing behavior separately.
    Delegated folder ownerR W C E M F AAccess Control permits trustee/IRF changes; does not confer Supervisor.
    Service accountDedicated group with minimum path-specific rightsAvoid security equivalence to Admin or broad container-level Supervisor.

    File and directory attributes   Back to contents

    Common attributes

    AttributeEffect / use
    Read OnlyPrevents file modification; older implementations may also imply rename/delete protection.
    ArchiveMarks a file as changed for archive-aware backup workflows.
    Hidden / SystemControls client visibility and marks operating-system content.
    ShareablePermits compatible shared access semantics.
    TransactionalEnables transaction tracking where supported.
    Purge ImmediateDeletes without retaining a salvageable copy.
    Rename InhibitPrevents renaming.
    Delete InhibitPrevents deletion.
    Copy InhibitRestricts copying where supported by the client/protocol path.

    Attribute support varies between Traditional and NSS volumes and between access protocols. A change is effective only when the underlying file system and NCP path can enforce it. [S6]

    Storage, volumes, and file systems   Back to contents

    Traditional file system versus NSS   Back to contents

    File-system comparison

    CharacteristicTraditional file systemNSS
    StructureNetWare partition containing one or more volumesDevices/partitions feed pools; pools contain logical volumes
    RecoveryVREPAIR on an unmounted volumeVERIFY/REBUILD and NSS-specific tools; VREPAIR is not used
    Mount behaviorDirectory/FAT structures can make large-volume recovery slowJournaling and modern metadata support faster activation
    Capacity modelFixed allocation within the NetWare partitionVolumes allocate pool space dynamically and can be overbooked
    NamespacesDOS plus added LONG/MAC/NFS namespacesMultiple namespaces integrated into NSS semantics
    Advanced featuresTrustees, salvage, compression on supported versionsTrustees, quotas, salvage, compression, snapshots/DFS options, encryption
    MigrationRequires metadata-aware copy and namespace planningDesigned for compatibility with OES NSS and NCP services

    NSS storage hierarchy   Back to contents

    1. Physical disks, SAN LUNs, RAID devices, virtual disks, or multipath devices are presented as storage devices.
    2. NSS partitions or segments allocate device space to one or more pools.
    3. A pool aggregates space and can span devices. Its failure domain therefore includes every device contributing segments.
    4. One or more NSS volumes allocate space from a pool only as needed. A volume belongs to one pool; a pool can contain multiple volumes.
    5. NCP, CIFS, AFP, NetStorage, and application services expose the volume through their configured identity and trustee model.

    NetWare 6.5 NSS supports dynamic volume growth within a pool and overbooking. The official guide describes volumes up to 8 TB and very large file counts, while individual devices presented to NetWare NSS are limited to 2 TB. Verify the exact build, device carving, and storage vendor limits before expansion. [S5]

    POOL FAILURE DOMAIN: Spanning a pool across devices increases capacity but also couples availability. Hardware RAID, NSS mirroring, SAN protection, multipathing, and backup are different controls; document which layer actually protects each segment.

    Namespaces and path compatibility   Back to contents

    A namespace records names and metadata for a client environment. Traditional volumes begin with DOS semantics and can add LONG for Windows/OS2, MAC for Macintosh, and NFS for Unix-style names. [S2]

    LOAD LONG.NAM
    ADD NAME SPACE LONG TO DATA

    REM Equivalent choices exist for MAC and NFS where the modules are installed.

    • Do not remove a namespace until every file name and metadata dependency has been assessed.
    • Migration tools may require the NFS namespace on a Traditional source volume to preserve names and metadata correctly.
    • Case, forbidden characters, alternate data, Macintosh metadata, and long-name collisions must be tested against the destination protocol.

    Salvage, purge, quotas, and capacity   Back to contents

    • Salvage retains deleted files until they are restored, purged, or reclaimed according to policy. It is not a backup because it shares the same volume and failure domain.
    • Purge permanently removes salvageable files. PURGE IMMEDIATE bypasses recovery for selected files/directories.
    • NSS can enable salvage per volume; NSS console commands include NSS /SALVAGE=volume and NSS /NOSALVAGE=volume. [S2, S5]
    • User, directory, and volume quotas control consumption. Always check the pool as well as the logical volume: an overbooked pool can exhaust physical space before volume quotas appear full.
    • Keep SYS for operating-system and extension content where practical; place user data and applications on separate pools/volumes. [S5]

    Repair boundaries   Back to contents

    Repair decision table

    TargetDiagnostic / repair familyBoundary
    Traditional volumeVOLUME/VOLUMES, MONITOR, VREPAIRDismount before VREPAIR; preserve logs and backup first.
    NSS volume/poolNSS /STATUS, NSSMU, VERIFY/REBUILD, iManager/NRMDo not use VREPAIR; confirm pool/device state before metadata repair.
    eDirectoryiMonitor, DSREPAIR, DSTRACEDirectory repair is separate from volume repair; start with health checks.
    Hardware/storage pathNWPA/driver tools, vendor array, mirror/RAID statusFile-system repair cannot correct a failing controller, path, or LUN.
    Application dataVendor consistency and recovery toolsA mounted volume does not prove a database or message store is consistent.

    Clients, drive mappings, and login scripts   Back to contents

    Client families   Back to contents

    Client generations

    ClientTypical environmentKey components / notes
    NETX requesterEarly DOS / BinderySmall conventional-memory requester; server-centric login.
    VLM clientDOS / NDSLSL + ODI LAN driver + IPXODI + VLM modules; NDS-aware.
    Client32Windows 3.x/9x32-bit client stack, NDS login, improved cache and transport support.
    Novell ClientWindows NT through supported later Windows releasesNCP, eDirectory authentication, SLP, mappings, trustee extensions.
    Novell Client for LinuxLinux workstationsNCP and eDirectory integration; some login-script commands differ.
    NetStorageBrowser/WebDAV-style accessInterprets selected MAP and conditional login-script commands.
    CIFS/AFP/NFSNative OS accessProtocol-specific identity mapping and metadata semantics; not identical to NCP.

    Path syntax and mappings   Back to contents

    Path examples

    FormExampleMeaning
    Current serverSYS:PUBLICPUBLIC directory on SYS of the current/default server.
    Server qualifiedNW65LAB/SYS:PUBLICPUBLIC on SYS of server NW65LAB.
    Object qualified.DATA.NW65LAB.SERVERS.ACME:PROJECTSDirectory under a Volume object identified from [Root].
    Drive mappingMAP G:=NW65LAB/DATA:PROJECTSMap G to the explicit server/volume path.
    Home mappingMAP H:=%HOME_DIRECTORYMap from the user’s eDirectory Home Directory property.
    Search driveMAP INS S1:=SYS:PUBLICInsert a program search mapping without replacing existing search drives.
    Fake rootMAP ROOT F:=SERVER/VOL:APPPresent APP as the apparent root for a legacy application.

    Login script execution order   Back to contents

    1. The container login script runs first and establishes defaults for users in that O or OU.
    2. The assigned Profile object’s login script runs next and adds role- or team-specific mappings.
    3. The User object’s login script runs last and can override earlier mappings.
    4. If the user has no user login script, the built-in default login script runs unless NO_DEFAULT was issued by a container or profile script. [S9]
    5. Prefer reusable container and profile scripts; reserve user scripts for true exceptions.
    6. Use IF MEMBER OF to drive group-based mappings, INCLUDE for shared text scripts, and MAP DISPLAY OFF/ON for clean output.
    7. The last conflicting MAP wins. Diagnose the full chain rather than only the user script.

    Login script example   Back to contents

    REM Container/Profile example – validate names and client behavior
    MAP DISPLAY OFF
    MAP ERRORS OFF
    MAP INS S1:=NW65LAB/SYS:PUBLIC
    MAP H:=%HOME_DIRECTORY

    IF MEMBER OF “.TEAM_ARCHITECTURE.ACME” THEN
      MAP G:=NW65LAB/DATA:ARCHITECTURE
    END

    IF MEMBER OF “.NETWARE_ADMINS.ACME” THEN
      MAP M:=NW65LAB/SYS:SYSTEM
    END

    MAP ERRORS ON
    MAP DISPLAY ON
    MAP

    TEST MATRIX: Test login scripts with each supported client family, transport, context, roaming site, and group combination. A script that works in the Windows Novell Client may be only partially implemented by the Linux client or NetStorage. [S9]

    Administration quick reference   Back to contents

    Primary administration tools   Back to contents

    Administration tool map

    ToolRuns atPrimary job
    System ConsoleServerCore commands, screen switching, NLM control, boot and emergency operation.
    MONITORServer consoleConnections, CPU, memory, service processes, storage, LAN statistics, SET parameters.
    NWCONFIGServer consoleDrivers, products, NCF editing, installation options, traditional volume tasks.
    INETCFG / TCPCONServer consoleProtocol configuration and live TCP/IP status/statistics.
    NSSMUServer consoleNSS devices, partitions, pools, volumes, RAID, and attributes.
    Novell Remote ManagerWeb browserHealth, console, modules, connections, volumes, parameters, logs, diagnostics. [S11]
    iManagerWeb browserRole-based eDirectory, NSS, files, rights, certificates, and service administration.
    ConsoleOne / NWAdminWorkstation or server GUIDirectory objects, schema, rights, login scripts, and product snap-ins.

    Console command quick reference   Back to contents

    Common server-console commands

    CommandPurposeNotes
    HELP [command] / HELP ALLShow console command helpPrefer local help because loaded modules register additional commands.
    VERSIONShow NetWare, support pack, license, and eDirectory versionsRecord before any change.
    CONFIGShow server, LAN, IPX, tree, and Bindery context informationUseful hardware/network baseline.
    TIMEShow server timeCompare with directory time sources.
    MODULES [prefix*]List loaded modules and address spacesUse before unload or abend analysis.
    SEARCHShow or modify NLM search pathsUnexpected paths can load the wrong module version.
    MEMORYShow installed/addressable memoryUse NRM for deeper attribution.
    DISPLAY PROCESSORSShow processor online/offline stateNetWare 5/6 multiprocessor environments.
    DISPLAY ENVIRONMENTShow search paths and SET parametersDISPLAY MODIFIED ENVIRONMENT shows deviations only.
    SETBrowse or change server parametersConfirm valid range and persistence file.
    MONITOROpen live system monitorConnections, resources, parameters, storage, LAN.
    LOAD / UNLOADLink or unlink an NLM or driverRespect dependencies and application shutdown procedure.
    PROTECT file.NCFLoad an NCF into a protected address spaceOnly for compatible modules.
    PROTECTIONList/configure protected spacesCan enable restart behavior.
    MOUNT volume / MOUNT ALLMount volumesUse NSS tools for NSS-specific activation issues.
    DISMOUNT volumeMake a volume unavailableClose files and stop dependent applications first.
    VOLUME / VOLUMESList mounted volumesSpelling varies by release/module registration.
    NSS /STATUS / NSS /HELPShow NSS state and helpNSS commands are version specific.
    NSSMUOpen NSS management utilityDestructive functions can erase device metadata.
    NWCONFIGOpen server configurationDriver/product/NCF and traditional storage tasks.
    INETCFG / TCPCONConfigure or monitor networkingSave before restart; distinguish configuration from live state.
    PING / TPINGTest IP reachabilityTPING syntax and implementation vary.
    DISPLAY SERVERSList SAP-advertised IPX servicesNot an IP/SLP discovery test.
    DISPLAY SLP …Show SLP agents, services, addresses, or typesExact subcommands depend on SLP.NLM build.
    DSREPAIRDirectory diagnostics and repairStart with time and sync reports.
    SET DSTRACE=…Control directory traceDisable filters/logging when complete.
    CONLOGCapture console messagesDefault SYS:ETC\CONSOLE.LOG; load early.
    DISABLE LOGIN / ENABLE LOGINControl new loginsExisting connections remain until cleared or logged out.
    SECURE CONSOLERestrict console operationsLoad required nonstandard-path modules first. [S2]
    DOWNOrderly shutdownFlushes caches, closes files, executes SHUTDOWN.NCF.
    RESTART SERVER [-NA|-NS]Orderly NetWare restartUse diagnostic switches deliberately.

    Workstation utility quick reference   Back to contents

    Common client/workstation utilities

    UtilityPurposeExample
    LOGINAuthenticate and execute login scriptsLOGIN TREE/USER or LOGIN SERVER/USER
    LOGOUTClose authenticated connectionsLOGOUT or client GUI equivalent
    MAPView/create/delete drive and search mappingsMAP G:=SERVER/VOL:PATH
    CXView/change eDirectory contextCX /T /A
    RIGHTSView/change file trustees, rights, IRF, and sourcesRIGHTS path /NAME=user /I
    FLAGView/change file or directory attributesSyntax varies; prefer client property page for safety
    SALVAGE / PURGERestore or permanently remove deleted filesUse client GUI or matching release utility
    CAPTURE / NPRINTLegacy queue-based print redirection/submitVersion and client dependent

    Core NLM quick reference   Back to contents

    Common modules – not exhaustive

    ModuleRoleOperational warning
    DS.NLMNDS/eDirectory engineDirectory-dependent services and authentication rely on it.
    NCP.NLM / CONNMGR.NLMCore NCP and connection servicesFoundation for client file service.
    NCPIP.NLMNCP over TCP/UDPUnloading removes IP NCP access. [S3]
    NCPIPX.NLMNCP over IPXLegacy transport; not intended for casual unload after activation.
    TCPIP.NLMTCP/IP stackLarge dependency tree; use INETCFG/TCPCON.
    IPXSPX.NLMIPX/SPX stackRequired by legacy IPX clients/services.
    SLP.NLM / SLPDA.NLMIP service discovery / Directory AgentScopes and directory replicas affect availability.
    NSS.NLMNovell Storage ServicesDo not unload with active NSS volumes or dependent services.
    NWPA.NLMStorage driver architectureHAM/CDM storage access depends on it. [S3]
    MONITOR.NLMSystem monitoringCan be loaded and unloaded as a utility.
    NWCONFIG.NLMServer configurationInstallation and driver operations can alter NCF files.
    DSREPAIR.NLMDirectory diagnostics/repairRepairs can change replicated state.
    CONLOG.NLMConsole loggingConfigure rotation; unlimited logs can consume SYS.
    PORTAL.NLM / HTTPSTK.NLMRemote Manager and HTTP stackLegacy web/TLS exposure requires containment.
    TIMESYNC.NLM / XNTPD.NLMTime synchronizationUse one planned time model; eDirectory depends on stable time.
    SMDR.NLM / TSAFS.NLM / SBCON.NLMStorage Management Services backupCoordinate application and directory-aware backup.
    SNMP.NLMMonitoring agentLegacy community-based SNMP is not suitable across untrusted networks.

    Illustrative NCF skeletons   Back to contents

    NOT PASTE-READY: Driver names, load order, bindings, addresses, and SET parameters must come from the target server’s known-good configuration and matching manuals. The skeletons show separation of concerns only.

    REM C:\NWSERVER\STARTUP.NCF – schematic only
    REM Pre-mount SET parameters validated for this exact release
    SET <pre-mount parameter> = <validated value>
    REM Platform, storage adapter, and device modules from known-good media
    LOAD <platform>.PSM
    LOAD <adapter>.HAM <validated parameters>
    LOAD <device>.CDM

    REM SYS:SYSTEM\AUTOEXEC.NCF – schematic only
    FILE SERVER NAME <SERVERNAME>
    LOAD CONLOG ARCHIVE=YES MAXIMUM=<validated-kilobytes>
    REM Load/bind LAN and protocols or invoke generated network configuration
    <known-good network configuration>
    REM Start directory, discovery, storage, management, and applications
    <service-specific NCF files>
    MOUNT ALL

    REM SYS:SYSTEM\SHUTDOWN.NCF – schematic only
    REM Stop application services in reverse dependency order
    <application stop commands>
    REM Flush/close product-specific engines before DOWN completes

    Operations runbook   Back to contents

    Daily, weekly, and monthly checks   Back to contents

    Operational cadence

    CadenceChecksEvidence to retain
    DailyServer up time; health summary; ABEND.LOG; SYS/pool free space; mirror/RAID/path state; backup completion; time state; critical service availabilityAlert record, console/health snapshot, backup result
    WeeklyDirectory sync for dynamic trees; CONSOLE.LOG and SYS$LOG.ERR review; NLM/application errors; packet buffers; LAN errors; salvage growth; sample restoreDSTRACE/DSREPAIR report, capacity trend, restore evidence
    MonthlyDirectory health for static trees; replica and partition inventory; DS versions; schema/obituary status; account review; recovery media and cold-image verificationSigned health report and configuration archive
    Before major changeFull directory health check; application-consistent backup; boot/config export; driver/media check; rollback rehearsal; maintenance communicationsChange record, hash/manifest, rollback decision point

    Controlled maintenance shutdown   Back to contents

    1. Confirm a current usable backup and record the current VERSION, up time, active modules, volume/pool status, mirror/RAID state, time status, and directory health.
    2. Notify users and application owners; quiesce or stop databases, message stores, print services, and backup jobs through their supported procedures.
    3. Issue DISABLE LOGIN. Review MONITOR connections and open files; have users close data and log out rather than clearing active sessions blindly.
    4. Dismount only the volumes required by the maintenance procedure. Confirm cluster or shared-storage ownership where applicable.
    5. Issue DOWN for an orderly shutdown. DOWN flushes cache, closes files, updates file-system structures, and runs SHUTDOWN.NCF if present. [S2]
    6. Wait for the completion message or return to DOS before powering off or rebooting hardware.
    7. After startup, validate volumes, directory synchronization, SLP/SAP discovery, applications, clients, logging, and backups before re-enabling normal access.

    Change preparation checklist   Back to contents

    • Exact server, support pack, eDirectory, NLM, driver, and hardware/virtual hardware versions recorded.
    • STARTUP.NCF, AUTOEXEC.NCF, SHUTDOWN.NCF, SYS:ETC configuration, driver set, and application NCF files copied and hashed.
    • Storage map records devices, partitions, pools, volumes, namespaces, quotas, trustee metadata, cluster resources, and free space.
    • Directory map records tree, partitions, replicas, Master roles, time sources, SLP scopes/DAs, CA host, licensing, and schema extensions.
    • Application-consistent backup and a directory-aware backup completed; representative restore tested.
    • Rollback is time-bounded, resourced, and tested; the point beyond which rollback is unsafe is explicit.
    • Management access remains available if clients, SLP, DNS, or the normal AUTOEXEC.NCF path fails.

    Troubleshooting playbooks   Back to contents

    Server will not start or SYS will not mount   Back to contents

    1. Capture the screen and preserve BOOT$LOG.ERR. Classify the failure as before STARTUP.NCF, during driver load, during storage discovery, during SYS mount, or after AUTOEXEC.NCF begins.
    2. Boot with SERVER -NA when SYS can mount but post-mount services fail. Use SERVER -NS or a known-good alternate startup file only when prepared to load required storage support manually.
    3. Compare STARTUP.NCF, platform support, HAM/CDM drivers, firmware, virtual hardware, and device presentation with the known-good baseline.
    4. Confirm the controller/LUN/device is present and stable before attempting file-system repair. A missing or changing device is not a metadata-repair problem.
    5. For a Traditional volume, use VREPAIR only while unmounted and after preserving evidence/backup. For NSS, use NSS status, NSSMU, and the appropriate VERIFY/REBUILD procedure; never VREPAIR an NSS volume.
    6. Once SYS mounts, start AUTOEXEC.NCF services in controlled groups to isolate the failing module or binding.

    Clients cannot find a server   Back to contents

    Discovery fault isolation

    CheckIP/SLP environmentIPX/SAP environment
    Basic reachabilityPING/TPING, routing, VLAN/firewall, DNSFrame type, external network number, router path
    Service discoverySLP scope, DA list, SYS:ETC\SLP.CFG, port 427DISPLAY SERVERS, SAP filters, hop count
    File serviceNCPIP.NLM, TCP/UDP 524, server object addressNCPIPX.NLM, IPX binding/socket
    Client settingsPreferred tree/server, SLP DA/scope, protocol orderPreferred server, frame type, network number
    Directory dependencyReplica reachability, NDAP service registrations, timeDirectory SAP service and route

    Authentication or login script failure   Back to contents

    1. Separate authentication failure from post-authentication login-script failure. Test a minimal login without application mappings where possible.
    2. Confirm user distinguished name, context, preferred tree/server, password status, account restrictions, and client date/time.
    3. Check server time and DSREPAIR Time Synchronization; then verify the required partition replica is reachable and synchronized.
    4. For legacy clients/applications, verify BINDERY CONTEXT and unique short names.
    5. Trace the container, profile, user, and default login scripts in order. Enable MAP errors and remove conditionals temporarily in a test account, not in production for every user.
    6. Verify that the user is a trustee of the Profile object and that mapped servers/volumes are reachable through the selected protocol. [S9]

    Access denied or files are invisible   Back to contents

    1. Confirm the exact path, server, volume, namespace, protocol, and user identity. Alias and Directory Map objects can conceal the real target.
    2. Use RIGHTS with /NAME and /I, or the client’s Current Effective Rights view, to identify direct, group, security-equivalent, and inherited rights.
    3. Inspect IRFs at every level from the relevant parent to the target. Confirm that Read and File Scan exist for visibility and content access.
    4. Inspect target file/directory attributes: Read Only, Hidden, Delete Inhibit, Rename Inhibit, Purge Immediate, and protocol-specific enforcement.
    5. Check user/directory/volume quotas, free pool space, open-file and record locks, ownership, and application-level permissions.
    6. Remember that rights on the eDirectory Volume object do not substitute for file-system trustee rights stored on the volume.

    Slow response or high utilization   Back to contents

    • Establish whether the delay is client-only, service-specific, server-wide, site-specific, or time-of-day dependent.
    • Use Novell Remote Manager or MONITOR for CPU, service processes, packet receive buffers, memory, connections, open files, LAN errors, and disk activity.
    • Check mirror/RAID state, controller errors, LUN latency, low SYS/pool space, salvage backlog, and concurrent backup/antivirus/application jobs.
    • Review SLP timeouts and DA availability for slow logins; review directory replica placement and time for slow authentication.
    • Record DISPLAY MODIFIED ENVIRONMENT. NetWare defaults were tuned as a balanced system; do not copy old tuning folklore without evidence. [S4]
    • If No ECB Available Count grows, investigate dropped packets, driver/TSM compatibility, and packet receive buffers; more buffers consume memory. [S4]

    Volume or pool is full   Back to contents

    1. Identify whether the constraint is a user quota, directory quota, logical volume quota, physical NSS pool, Traditional partition, SYS, or underlying storage device.
    2. Stop the process generating data before deleting evidence or expanding storage.
    3. Review salvageable files and purge only under an approved retention decision. Salvage is shared-capacity recovery, not free space.
    4. For NSS, check every volume in the pool and account for overbooking. Extend the pool only after validating device size, RAID/path protection, backups, and vendor limits.
    5. For SYS, remove or rotate logs and temporary/support-pack content only when ownership is known. Do not delete hidden directory or product files by pattern.
    6. After remediation, restore alert thresholds, logging rotation, quota controls, and capacity trend monitoring.

    Abend or repeated restart   Back to contents

    1. Preserve the abend screen, ABEND.LOG, CONSOLE.LOG, core dump if configured, MODULES list, application logs, and the exact preceding change/workload.
    2. Prevent an uncontrolled restart loop. Automatic restart can hide recurring abends; check ABEND.LOG and server up time routinely. [S2, S4]
    3. Identify the faulting NLM, address space, thread, and dependency chain. Determine whether it ran in the kernel or a protected space.
    4. Reproduce only in an isolated clone with matching data and versions. Do not swap NLMs across support packs merely because file names match.
    5. If a protected application space faults, review restart/no-restart policy and product recovery semantics before reloading it.
    6. Treat resulting file-system or application inconsistency separately; a recovered kernel does not prove data consistency.

    eDirectory synchronization errors   Back to contents

    1. Run the directory health sequence: versions, time synchronization, replica synchronization, schema synchronization, obituaries, and external references.
    2. Verify IP/IPX reachability, NCP/NDAP service addresses, SLP/SAP discovery, DNS, firewall rules, and the replica ring’s server objects.
    3. Use DSREPAIR Report Synchronization Status and DSTRACE filters to collect the error and affected partition; seek All Processed = Yes for healthy rings. [S10]
    4. Resolve time, connectivity, name/address, disk-space, and version defects before repairing the directory database.
    5. Back up directory state and record replica roles before partition, replica, or obituary repairs. Coordinate changes across every server in the ring.

    Backup and disaster recovery   Back to contents

    What a usable backup must preserve   Back to contents

    Recovery asset inventory

    AssetPreserveWhy
    Boot environmentDOS partition/image, SERVER.EXE, STARTUP.NCF, AUTOEXEC.BAT, driversNeeded before SYS and network services are available.
    SYS configurationAUTOEXEC.NCF, SHUTDOWN.NCF, SYS:ETC, NLM/application config, logsReconstructs service identity and load order.
    DirectorySupported NDS/eDirectory backup, schema, partitions/replicas, certificatesA file copy of the live DIB is not a supported directory backup.
    File dataFiles plus trustees, IRFs, ownership, attributes, namespaces, quotas, linksA generic SMB copy can lose NetWare metadata and security.
    ApplicationsVendor-consistent database/message-store backup and transaction logsVolume-level consistency does not ensure application consistency.
    Storage mapController/LUN/RAID, devices, partitions, pools, volumes, cluster resourcesRequired to present the same data in the same ownership model.
    Software entitlementInstall/overlay media, support packs, patches, drivers, licenses, keysDownloads and activation services may no longer be obtainable.
    Operational evidenceRunbooks, credentials escrow, dependencies, test results, hashesTurns backup media into a repeatable recovery.

    BACKUP SEMANTICS: Use Storage Management Services or another NetWare-aware product for trustee and namespace fidelity, plus an application-aware method for databases and directory services. Test the exact restore path; a successful backup job is not evidence of recoverability.

    Recovery rehearsal   Back to contents

    1. Create an isolated recovery network with no route to production and a controlled time/DNS/SLP design.
    2. Recover the boot environment and virtual/physical hardware drivers, then start with normal NCF files suppressed if necessary.
    3. Present storage consistently and recover SYS before application/data volumes. Validate TFS/NSS type before any repair action.
    4. Restore the directory using its supported method and intended replica topology. Avoid creating duplicate server or tree identities on a connected network.
    5. Restore file data with trustees, IRFs, ownership, attributes, quotas, and namespaces, then application data with vendor consistency checks.
    6. Test representative authentication, login scripts, rights, mappings, locks, salvage, print, backup, and application transactions.
    7. Record recovery time, manual decisions, missing assets, and new hashes. Update the runbook and repeat until another engineer can execute it.

    Printing and ancillary services   Back to contents

    Printing generations   Back to contents

    NetWare printing models

    ModelCore objects/servicesClient experience
    Queue-based printingPrint Queue, Printer, Print Server; PSERVER; CAPTURE/NPRINTLPT redirection or queue submission; common in 3.x/4.x.
    NDPSBroker, Manager, Printer Agent; NDPSMDirectory-discovered printers, driver distribution, status and notification.
    iPrintIPP-based print services and web installationBrowser/client printer installation and IP transport; mature in 6.x/OES.
    • Inventory printer agents, gateways, drivers, queues, ports, DNS names, and application dependencies before migration.
    • A user can authenticate and map drives successfully while printing fails through an independent Broker/Manager/gateway path.
    • Legacy printer drivers are executable code. Preserve them for recovery but do not deploy them to unsupported modern clients without containment and testing.

    Other common services   Back to contents

    Common optional services

    ServiceTypical roleMigration/containment note
    DNS/DHCPDirectory-integrated network servicesExport zones, subnets, options, and service-object dependencies.
    NetStorageWeb access to NCP/CIFS-backed filesIsolate old web/TLS; login-script support is partial.
    iFolderUser file synchronizationInventory clients, stores, policies, and conflict behavior.
    Apache/Tomcat/MySQL/PHPWeb/application platform on 6.5Version-specific security/consistency; migrate rather than expose.
    GroupWiseMessaging and collaborationUse product-specific domain, post-office, and agent migration.
    Btrieve/PervasiveTransactional database engineCoordinate shutdown, logs, locks, and version compatibility.
    Cluster ServicesFailover for volumes and servicesPreserve virtual NCP identity, scripts, preferred nodes, and shared storage.
    SMS backupTSA/SMDR/SBCON backup frameworkRecord agent, media, catalog, encryption, and restore dependencies.

    Containment, preservation, and migration   Back to contents

    Minimum containment pattern   Back to contents

    1. Place NetWare and any dependent legacy clients on a dedicated VLAN or virtual switch with no direct Internet route.
    2. Default-deny at the firewall. Permit NCP, SLP, DNS, NTP, backup, directory, print, and application flows only between documented endpoints.
    3. Use a hardened jump host with the compatible Novell Client and management tools. Reach the jump host through modern MFA and encrypted remote access.
    4. Send logs and monitoring outward through a controlled relay or poll from a collector; do not install untested modern agents into the NetWare kernel.
    5. Keep offline, immutable copies of installation media, patches, drivers, configuration, license artifacts, system images, and data backups.
    6. Set an explicit retirement date and risk owner. Containment reduces exposure; it does not make unsupported code supportable.

    Migration sequence   Back to contents

    Staged migration

    StageActivitiesExit criterion
    DiscoverInventory services, directory roles, applications, volumes, trustees, clients, print, protocols, and dependenciesAuthoritative dependency and data map approved
    StabilizePatch to the approved terminal level, fix time/replication/storage errors, test backup and restoreHealthy, repeatable source baseline
    DesignSelect supported OES/Enterprise Server, Windows/Linux, SaaS, or application-specific destinations; map identity and rightsTarget architecture and rollback signed off
    PilotMigrate representative users/data/printers/apps with metadata-aware toolsFunctional, security, performance, and recovery tests pass
    CoexistIntroduce target services, NCP/CIFS/client changes, DNS/SLP updates, and staged data synchronizationUsers operate on target with measured exceptions
    Cut overQuiesce source, final sync, redirect mappings/services, validate rights and applicationsBusiness acceptance and rollback decision closed
    RetireRemove applications, replicas, service objects, licenses, routes, and storage in supported orderNo hidden dependency; evidence and retention complete

    METADATA-AWARE COPY: Use the supported migration/consolidation tool or an NSS/NCP-aware process when trustee assignments, IRFs, ownership, namespaces, Macintosh metadata, quotas, or application attributes matter. Generic drag-and-drop or SMB copies are not equivalent. [S12, S15]

    Virtualization and historical preservation   Back to contents

    • NetWare 6.5 SP8 documented VMware and Xen guest deployments, but compatibility depends on virtual CPU, storage, network adapter, and driver choices. [S1]
    • Preserve the original disk images before converting formats. Work on a verified copy and record hashes before and after transformation.
    • Keep the virtual NIC disconnected during the first boot of a clone to prevent duplicate server names, internal network numbers, tree identities, or replica activity.
    • Match old virtual hardware where possible. A newer hypervisor’s default controller or NIC may have no NetWare driver.
    • Capture console video/screens, configuration, volumes, application behavior, and client workflow as part of preservation, not only a bootable VM.
    • If the goal is evidence or data extraction rather than continued service, prefer an offline, read-only recovery workflow over production resurrection.

    Appendix A – Common paths and files   Back to contents

    Locations commonly encountered on NetWare 4.x-6.5

    LocationContents / use
    C:\NWSERVER\SERVER.EXENetWare server loader/kernel image.
    C:\NWSERVER\STARTUP.NCFPre-SYS SET parameters and platform/storage drivers.
    C:\NWSERVER\BOOT$LOG.ERRBoot messages/errors according to logging configuration.
    C:\ABEND.LOG then SYS:SYSTEM\ABEND.LOGAbend record before and after restart/copy.
    SYS:SYSTEMCore NLMs, AUTOEXEC.NCF, SHUTDOWN.NCF, utilities, application start files.
    SYS:PUBLICClient utilities and management program files.
    SYS:LOGINFiles accessible during login and pre-authentication workflows.
    SYS:ETCNetwork/service configuration and logs, including SLP.CFG and CONSOLE.LOG.
    SYS:ETC\CONSOLE.LOGDefault CONLOG output.
    SYS:SYSTEM\DSTRACE.DBGDirectory trace output when trace-to-file is enabled.
    SYS:_NETWAREHidden/system directory containing directory database and security data; never treat as ordinary file content.
    SYS:SYSTEM\SYS$LOG.ERRCommon system error log location on many releases.
    volume-root\VOL$LOG.ERRTraditional volume error/repair log commonly found at a volume root.

    VERSION VARIANCE: Paths can be redirected, clustered, or changed by products and support packs. Treat this appendix as a discovery list, then confirm with CONFIG, SEARCH, module parameters, NCF files, and the matching manual.

    Appendix B – Glossary   Back to contents

    Glossary

    TermDefinition
    AbendAbnormal end: a NetWare fault or exception that can suspend a thread, fault an address space, or stop/restart the server.
    BinderyPer-server flat database of users, groups, properties, and services used primarily by NetWare 2.x/3.x.
    Bindery contextOne or more eDirectory containers exposed as a flat Bindery view for legacy clients/applications.
    CDMCustom Device Module in the NetWare Peripheral Architecture storage stack.
    DIBDirectory Information Base: the local NDS/eDirectory database.
    Directory MapeDirectory object that represents a path and reduces hard-coded mapping dependencies.
    Distinguished nameAn object’s unique hierarchical name in the eDirectory tree.
    eDirectoryLater name and evolution of Novell Directory Services (NDS).
    HAMHost Adapter Module: storage adapter driver in NWPA.
    IRFInherited Rights Filter: blocks selected rights inherited through a hierarchy.
    IPX/SPXLegacy Novell routed network and connection-oriented transport protocol suite.
    NCPNetWare Core Protocol: client/server file and network service protocol.
    NCFNetWare Command File: a server-side batch/configuration file.
    NDSNovell Directory Services: distributed directory introduced with NetWare 4.
    NDPSNovell Distributed Print Services, the directory-based successor to queue printing.
    NamespaceFile-name and metadata representation for DOS, LONG/Windows, Macintosh, NFS, or other clients.
    NLMNetWare Loadable Module: executable server component linked into the runtime.
    NSSNovell Storage Services: journaling file system and storage-pool/volume architecture.
    NWPANetWare Peripheral Architecture for HAM/CDM-based storage drivers.
    ODIOpen Data-Link Interface used by classic Novell client LAN/protocol stacks.
    OESOpen Enterprise Server, the Linux-based successor platform for eDirectory, NCP, NSS, iPrint, and related services.
    PartitionContiguous subtree replicated as a unit in NDS/eDirectory.
    PSMPlatform Support Module for processor/chipset/platform integration.
    ReplicaCopy of a directory partition held by a server; types include Master, Read/Write, Read-Only, and Subordinate Reference.
    Replica ringSet of servers holding replicas of the same partition.
    SAPService Advertising Protocol used to advertise services in IPX networks.
    SalvageRecovery of files retained after deletion but before purge/reclamation.
    SLPService Location Protocol used for IP service discovery and registration.
    SMSStorage Management Services: NetWare backup architecture using agents such as TSA and SMDR.
    TFSTraditional NetWare File System, distinct from NSS.
    TrusteeUser, group, or object assigned rights to a target directory, file, or directory object.
    VLMVirtual Loadable Module client architecture used by DOS NDS-aware clients.
    VolumeNamed NetWare file-system container such as SYS or DATA, exposed through NCP and represented by an eDirectory object in NDS-era systems.

    Appendix C – Official source set   Back to contents

    Sources were selected from surviving Novell, Micro Focus, NetIQ, and OpenText documentation. They were accessed on 8 August 2026. Product pages and document hosts can move; retain local archival copies where licensing permits.

    [S1] NW 6.5 SP8 Installation Guide. Open official source

    [S2] NW 6.5 SP8 Utilities Reference. Open official source

    [S3] NW 6.5 SP8 NLM Reference. Open official source

    [S4] NW 6.5 SP8 Server Operating System Administration – Troubleshooting. Open official source

    [S5] NW 6.5 SP8 NSS File System Administration Guide. Open official source

    [S6] NW 6.5 SP8 File Systems Management Guide – attributes and trustees. Open official source

    [S7] NW 6.5 SP8 Planning and Implementation Guide. Open official source

    [S8] NetIQ eDirectory 8.8 SP8 Administration Guide – eDirectory Rights. Open official source

    [S9] Novell Login Scripts Guide. Open official source

    [S10] NDS/eDirectory Health Check Procedures – Cross Platform. Open official source

    [S11] NW 6.5 SP8 Novell Remote Manager Administration Guide. Open official source

    [S12] Open Enterprise Server – Coexistence and Migration of File Services. Open official source

    [S13] OpenText Product Support Lifecycle. Open official source

    [S14] SLP Design and Implementation Guidelines. Open official source

    [S15] Novell Server Consolidation and Migration Toolkit. Open official source

    EDITION NOTE: This reference deliberately avoids prescribing hardware-specific driver lines, destructive repair options, or a current migration destination without an environment inventory. Those decisions must be made against the exact server state and the current support/interoperability matrix.

  • WordPress

    WordPress

    WordPress is a powerful content management system (CMS) that can be used to create and manage your website. It is an open source platform, meaning it is free to use and modify. WordPress is the most popular CMS in the world, powering about 35% of all websites on the internet.

    This guide will provide an brief overview of WordPress and how to get started using it.

    What is WordPress?

    WordPress is a content management system (CMS) that allows users to create and manage websites without needing to know any coding or web development skills. It was first released in 2003 and has since become the most popular CMS in the world, powering about 35% of all websites on the internet today. WordPress is open source software, meaning it is free to use and modify for any purpose you wish.

    Benefits of Using WordPress

    WordPress offers many benefits for website owners, including:

    • Easy to use – With its intuitive user interface, anyone can quickly learn how to use WordPress without needing any technical knowledge or experience with web development or coding languages.
    • Flexible – With thousands of themes and plugins available, you can customize your website to look exactly how you want it to look and add any features you need for your website’s functionality.
    • Secure – WordPress has built-in security features that help protect your website from malicious attacks and hackers.
    • SEO friendly – WordPress makes it easy to optimize your website for search engines so that your content can be easily found by potential visitors online.

    Installing WordPress


    Installing WordPress on your server requires a few steps:

    • Decide either to use a manged service or host your own.
    • Download the latest version of WordPress from wordpress.org/download/.
    • Upload the files to your server via FTP or SSH (Secure Shell).
    • Create a MySQL database for your installation using cPanel or phpMyAdmin (if available).
    • Run the installation script by visiting http://yourdomainname/wp-admin/install.php in your browser window (replace “yourdomainname” with your actual domain name).

    Setting Up Your Website

    Once you have installed WordPress, you will need to set up your website before you can start adding content or customizing it with themes and plugins:

    • Choose a theme – You can choose from thousands of free or premium themes available on wordpress.org/themes/.
    • Install plugins – Plugins are small pieces of software that add additional features and functionality to your website such as contact forms, ecommerce solutions, etc., which can be found at wordpress.org/plugins/.

    Working with Themes and Plugins


    Once you have installed a theme and plugins for your website, you will need to configure them properly so they work correctly:

    • Configure theme settings – Most themes come with their own settings page where you can customize various aspects such as colors, fonts, layouts, etc., so make sure you take some time to go through these settings and adjust them according to your preferences before moving on to other tasks like adding content or installing plugins.
    • Configure plugin settings – Each plugin will have its own settings page where you can configure various options such as enabling certain features or setting up payment gateways if applicable. Make sure you take some time to go through each plugin’s settings page so that everything works correctly when visitors come to your site.

    Managing Content

    Once you have set up your website with a theme and plugins, it’s time to start adding content! You can do this by creating posts or pages in the admin area of your site:

    • Create posts – Posts are short pieces of content such as blog posts or news articles that are displayed in reverse chronological order on the homepage of your site . To create a post , go to Posts > Add New in the admin area.
    • Create pages – Pages are static pieces of content such as About Us pages or Contact Us pages that are not displayed on the homepage but rather accessed directly via their own URL . To create a page , go to Pages > Add New in the admin area .

    SEO Best Practices

    Search engine optimization (SEO) helps ensure that people searching online for topics related to yours will find your website more easily . Here are some tips for optimizing your site for search engines :

    • Use keywords throughout your content – Make sure each post or page includes relevant keywords related to its topic so search engines can more easily find it when someone searches for those terms.
    • Optimize titles & meta descriptions – Titles should include relevant keywords while meta descriptions should provide an accurate summary of what visitors will find when they click through from search results.
    • Use internal links – Linking between different pages on your site helps search engines understand how all the different parts of it fit together.

    Security Tips

    Keeping your site secure is essential if you want visitors coming back again and again without worrying about their data being compromised . Here are some tips for keeping things secure :

    • Use strong passwords & two-factor authentication – Make sure all user accounts have strong passwords that cannot be easily guessed , as well as two-factor authentication enabled if possible .
    • Keep everything updated – Make sure all themes , plugins , and core software are kept up-to-date with the latest versions so any security vulnerabilities are patched quickly .
    • Monitor activity & backups regularly– Regularly monitor activity logs for suspicious activity , as well as backing up all data regularly just in case something goes wrong .

    Troubleshooting Common Issues

    From time-to-time , issues may arise when working with WordPress due to conflicts between themes , plugins , or other software running on the same server. Here are some tips for troubleshooting common issues :

    • Check error logs & debug mode– Check error logs in cPanel or phpMyAdmin for clues about what might be causing an issue , as well as enabling debug mode in wp-config file which will display errors directly on screen instead of hiding them away from view.
    • Disable conflicting plugins & themes– If an issue appears after installing a new plugin or theme, try disabling them one at a time until the issue disappears then contact support if necessary.