<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://research.iat.sfu.ca/research/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Hha13</id>
	<title>Research - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://research.iat.sfu.ca/research/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Hha13"/>
	<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/Special:Contributions/Hha13"/>
	<updated>2026-08-27T07:37:35Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.42.1</generator>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5280</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5280"/>
		<updated>2011-03-30T04:01:14Z</updated>

		<summary type="html">&lt;p&gt;Hha13: adding info about new features&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
Click on an item in the menu on the left, such as &#039;&#039;&#039;Objects&#039;&#039;&#039;, &#039;&#039;&#039;Purchases&#039;&#039;&#039;, &#039;&#039;&#039;Categories&#039;&#039;&#039;, etc.. These links will bring you to a page where you can view a list of all the Objects, Purchases, etc., and where you can filter or search for more specific ones.&lt;br /&gt;
&lt;br /&gt;
* To view an item&#039;s details, simply click on its name.&lt;br /&gt;
* To search for a particular item, enter your search term in the search bar (top right) and click Enter.&lt;br /&gt;
* To filter the items by a particular property, click on the property you want to filter by on the right. If you don&#039;t see the property you want to filter by, click &#039;&#039;&#039;Show All&#039;&#039;&#039; and a list of all existing properties will be displayed.&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
== Adding Items == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
Before starting:&lt;br /&gt;
&lt;br /&gt;
* If you are adding a new category, you will need a Manufacturer to be already created. Check whether the manufacturer of the object exists in the database, if not add it.&lt;br /&gt;
* If you are adding a new purchase, you will need a Vendor to be already created. Check whether the manufacturer of the object exists in the database, if not add it.&lt;br /&gt;
* If you are adding a new purchase, you will also need to know the purchase date and total. Other optional information that is good to have are the purchase order, invoice number, requisition number, or any other relevant details.&lt;br /&gt;
* This goes without saying, but the object you want to add should also have a yellow Research barcode sticker attached to it :)&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
Step 1 - Selecting or adding a category:&lt;br /&gt;
&lt;br /&gt;
* Click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to Objects in the menu on the left.&lt;br /&gt;
* Start typing the name of the category for the object in the box.&lt;br /&gt;
* If the category is found, click on it then click &#039;&#039;&#039;Continue&#039;&#039;&#039;.&lt;br /&gt;
* If the category is not found, click e &amp;quot;...or, add a new category +&amp;quot; to expand the form. Fill in the information then click &#039;&#039;&#039;Add &amp;amp; Continue&#039;&#039;&#039;. Note that the manufacturer must already exist when adding a new category.&lt;br /&gt;
&lt;br /&gt;
Step 2 - Selecting or adding a purchase:&lt;br /&gt;
&lt;br /&gt;
* Start typing the name of the purchase in the box.&lt;br /&gt;
* If the purchase is found, click on it then click &#039;&#039;&#039;Continue&#039;&#039;&#039;.&lt;br /&gt;
* If the purchase is not found, click on the &amp;quot;...or, add a new purchase +&amp;quot; to expand the form. Fill in the information then click &#039;&#039;&#039;Add &amp;amp; Continue&#039;&#039;&#039;. Note that the vendor must already exist when adding a new purchase.&lt;br /&gt;
&lt;br /&gt;
Step 3 - Fill in the object form&lt;br /&gt;
&lt;br /&gt;
* Type in the name of the object and use the barcode scanner to enter its yellow barcode. Fill in any other information and click &#039;&#039;&#039;Create Object&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;br /&gt;
To access the Kiosk for checking items in our out, click on &#039;&#039;&#039;Home&#039;&#039;&#039; in the menu on the left. To check items in:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check in, one at a time.&lt;br /&gt;
* After you have scanned them all, click &#039;&#039;&#039;Check In&#039;&#039;&#039;.&lt;br /&gt;
* If the Check In button is grey-ed out, it means that some items have never been checked out. Click the red X next to their name to remove them from the list, and the Check In button will become active. See below for how to check items out.&lt;br /&gt;
&lt;br /&gt;
To check items out:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check out, one at a time.&lt;br /&gt;
* Scan the library card of an existing user whose library card is matched to their profile in the same way. See above for how to match a library card or add a new user.&lt;br /&gt;
* After you have scanned all items and a single library card, click &#039;&#039;&#039;Check Out&#039;&#039;&#039;.&lt;br /&gt;
* If the Check Out button is grey-ed out, it means that some items are still on loan and cannot be checked in. Click the red X next to their name to remove them from the list, and the Check Out button will become active. See above for how to check items in.&lt;br /&gt;
&lt;br /&gt;
== Editing or Deleting Items ==&lt;br /&gt;
The process for editing or deleting an item is quite simple. Find an item you want to edit/delete (such as an object, a category, etc.) and browse to its detail page. Then simply click the edit/delete link on the right-hand side of the page. Note that deleting an item does not remove it from the database, instead it just marks it as deleted. You can always un-delete an item (this is also easy - the delete button you used to mark it as delete it will change to &#039;un-delete&#039; once deleted. Just click it!). You can also filter your searches when browsing items by including all items (default is only non-deleted items). Also note that it is impossible to check a deleted item out.&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Booking_Research_Rooms&amp;diff=5279</id>
		<title>Booking Research Rooms</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Booking_Research_Rooms&amp;diff=5279"/>
		<updated>2011-03-25T20:48:55Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Go to https://connect.sfu.ca/ and log in with your SFU credentials, as you normally would.  Select the Calendar tab, right click on the day for the booking and click &#039;New Appointment&#039;; you should see the Quick Add popup, like this:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen1.png|frame|center|Quick Add for making a calendar appointment]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Click on the More Details (lower left).  You should now see the expanded Appointment Details screen:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen2.png|frame|center|More Details for making a calendar appointment]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Click on Find Locations (upper middle tab).  Now, you should be looking at something like the screen shot below; for Name, provide a room (I have used the room-number 3950), and click Search.  The system will suggest matches; if more than one result is found, highlight the one you want and click Select at the bottom middle:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen3.png|frame|center|Find Locations for making a calendar appointment.  Partial room-name/number is enough to search with.]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Click on the Appointment Details tab, you should see something similar to the screenshot below - notice that the Location has now been filled in, and a Resources entry&lt;br /&gt;
appears under the Attendees box.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen4.png|frame|center|Completed Location, for Appointment Details]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
If you want to check the availability of a room or Attendees, after you have made the Location and Attendee selections, click on Schedule tab:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen5.png|frame|center|Checking for available times, for all attendees and room-resources]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Late-breaking news:  you can now use AutoComplete for the room name/number, right from the Quick Add screen; enter any portion of the room name or number, and a drop-down selection will appear, allowing you to choose the exact item you want:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Add_appt_screen6.png|frame|center|QuickAdd, showing autocompletion]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5240</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5240"/>
		<updated>2011-01-15T01:23:38Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
We try to align the research usernames with an existing SFU Computing ID.  This reduces confusion, and if the user chooses to also align their passwords, this gives the illusion of a single, seamless set of credentials across SFU / SIAT Research.&lt;br /&gt;
&lt;br /&gt;
However, about 50% of our research users are non-SFU people.  It is for this reason we run our own LDAP authentication server, and maintain our own users (as an aside, we also encrypt/store passwords in four different formats, which include suitable format for our SGI supercomputers, Linux workstations, Mac OS-X and two variations of Windows - this variety of password encryption is another reason we run local authentication).&lt;br /&gt;
&lt;br /&gt;
For a non-SFU user, we create their username  by period-separating their first and last names:&lt;br /&gt;
 &#039;&#039;&#039;Non-SFU&#039;&#039;&#039; userid creation:&lt;br /&gt;
 &lt;br /&gt;
 &#039;&#039;&#039;firstname.lastname&#039;&#039;&#039; (for example:  &#039;&#039;john.doe&#039;&#039;)&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
This creates a project for the user, and adds a web folder, hosted via hercules00. If the user just wants places for their files, skip the htdocs and htlogs stuff, and skip all the hercules config.&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user:root /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$username@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5239</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5239"/>
		<updated>2011-01-15T01:23:09Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
We try to align the research usernames with an existing SFU Computing ID.  This reduces confusion, and if the user chooses to also align their passwords, this gives the illusion of a single, seamless set of credentials across SFU / SIAT Research.&lt;br /&gt;
&lt;br /&gt;
However, about 50% of our research users are non-SFU people.  It is for this reason we run our own LDAP authentication server, and maintain our own users (as an aside, we also encrypt/store passwords in four different formats, which include suitable format for our SGI supercomputers, Linux workstations, Mac OS-X and two variations of Windows - this variety of password encryption is another reason we run local authentication).&lt;br /&gt;
&lt;br /&gt;
For a non-SFU user, we create their username  by period-separating their first and last names:&lt;br /&gt;
 &#039;&#039;&#039;Non-SFU&#039;&#039;&#039; userid creation:&lt;br /&gt;
 &lt;br /&gt;
 &#039;&#039;&#039;firstname.lastname&#039;&#039;&#039; (for example:  &#039;&#039;john.doe&#039;&#039;)&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
This creates a project for the user, and adds a web folder, hosted via hercules00. If the user just wants places for their files, skip the htdocs and htlogs stuff, and skip all the hercules config.&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$username@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5238</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5238"/>
		<updated>2011-01-15T01:22:31Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
We try to align the research usernames with an existing SFU Computing ID.  This reduces confusion, and if the user chooses to also align their passwords, this gives the illusion of a single, seamless set of credentials across SFU / SIAT Research.&lt;br /&gt;
&lt;br /&gt;
However, about 50% of our research users are non-SFU people.  It is for this reason we run our own LDAP authentication server, and maintain our own users (as an aside, we also encrypt/store passwords in four different formats, which include suitable format for our SGI supercomputers, Linux workstations, Mac OS-X and two variations of Windows - this variety of password encryption is another reason we run local authentication).&lt;br /&gt;
&lt;br /&gt;
For a non-SFU user, we create their username  by period-separating their first and last names:&lt;br /&gt;
 &#039;&#039;&#039;Non-SFU&#039;&#039;&#039; userid creation:&lt;br /&gt;
 &lt;br /&gt;
 &#039;&#039;&#039;firstname.lastname&#039;&#039;&#039; (for example:  &#039;&#039;john.doe&#039;&#039;)&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
This creates a project for the user, and adds a web folder, hosted via hercules00. If the user just wants places for their files, skip the htdocs and htlogs stuff, and skip all the hercules config.&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htlogs&lt;br /&gt;
 # chmod 755 /mnt/raid/projects/$project/htlogs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user:root /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$username@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5232</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5232"/>
		<updated>2010-11-17T01:54:26Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Objects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
Click on an item in the menu on the left, such as &#039;&#039;&#039;Objects&#039;&#039;&#039;, &#039;&#039;&#039;Purchases&#039;&#039;&#039;, &#039;&#039;&#039;Categories&#039;&#039;&#039;, etc.. These links will bring you to a page where you can view a list of all the Objects, Purchases, etc., and where you can filter or search for more specific ones.&lt;br /&gt;
&lt;br /&gt;
* To view an item&#039;s details, simply click on its name.&lt;br /&gt;
* To search for a particular item, enter your search term in the search bar (top right) and click Enter.&lt;br /&gt;
* To filter the items by a particular property, click on the property you want to filter by on the right. If you don&#039;t see the property you want to filter by, click &#039;&#039;&#039;Show All&#039;&#039;&#039; and a list of all existing properties will be displayed.&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
Before starting:&lt;br /&gt;
&lt;br /&gt;
* If you are adding a new category, you will need a Manufacturer to be already created. Check whether the manufacturer of the object exists in the database, if not add it.&lt;br /&gt;
* If you are adding a new purchase, you will need a Vendor to be already created. Check whether the manufacturer of the object exists in the database, if not add it.&lt;br /&gt;
* If you are adding a new purchase, you will also need to know the purchase date and total. Other optional information that is good to have are the purchase order, invoice number, requisition number, or any other relevant details.&lt;br /&gt;
* This goes without saying, but the object you want to add should also have a yellow Research barcode sticker attached to it :)&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
Step 1 - Selecting or adding a category:&lt;br /&gt;
&lt;br /&gt;
* Click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to Objects in the menu on the left.&lt;br /&gt;
* Start typing the name of the category for the object in the box.&lt;br /&gt;
* If the category is found, click on it then click &#039;&#039;&#039;Continue&#039;&#039;&#039;.&lt;br /&gt;
* If the category is not found, click e &amp;quot;...or, add a new category +&amp;quot; to expand the form. Fill in the information then click &#039;&#039;&#039;Add &amp;amp; Continue&#039;&#039;&#039;. Note that the manufacturer must already exist when adding a new category.&lt;br /&gt;
&lt;br /&gt;
Step 2 - Selecting or adding a purchase:&lt;br /&gt;
&lt;br /&gt;
* Start typing the name of the purchase in the box.&lt;br /&gt;
* If the purchase is found, click on it then click &#039;&#039;&#039;Continue&#039;&#039;&#039;.&lt;br /&gt;
* If the purchase is not found, click on the &amp;quot;...or, add a new purchase +&amp;quot; to expand the form. Fill in the information then click &#039;&#039;&#039;Add &amp;amp; Continue&#039;&#039;&#039;. Note that the vendor must already exist when adding a new purchase.&lt;br /&gt;
&lt;br /&gt;
Step 3 - Fill in the object form&lt;br /&gt;
&lt;br /&gt;
* Type in the name of the object and use the barcode scanner to enter its yellow barcode. Fill in any other information and click &#039;&#039;&#039;Create Object&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;br /&gt;
To access the Kiosk for checking items in our out, click on &#039;&#039;&#039;Home&#039;&#039;&#039; in the menu on the left. To check items in:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check in, one at a time.&lt;br /&gt;
* After you have scanned them all, click &#039;&#039;&#039;Check In&#039;&#039;&#039;.&lt;br /&gt;
* If the Check In button is grey-ed out, it means that some items have never been checked out. Click the red X next to their name to remove them from the list, and the Check In button will become active. See below for how to check items out.&lt;br /&gt;
&lt;br /&gt;
To check items out:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check out, one at a time.&lt;br /&gt;
* Scan the library card of an existing user whose library card is matched to their profile in the same way. See above for how to match a library card or add a new user.&lt;br /&gt;
* After you have scanned all items and a single library card, click &#039;&#039;&#039;Check Out&#039;&#039;&#039;.&lt;br /&gt;
* If the Check Out button is grey-ed out, it means that some items are still on loan and cannot be checked in. Click the red X next to their name to remove them from the list, and the Check Out button will become active. See above for how to check items in.&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5231</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5231"/>
		<updated>2010-11-17T00:57:41Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Checking Items In and Out */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
Click on an item in the menu on the left, such as &#039;&#039;&#039;Objects&#039;&#039;&#039;, &#039;&#039;&#039;Purchases&#039;&#039;&#039;, &#039;&#039;&#039;Categories&#039;&#039;&#039;, etc.. These links will bring you to a page where you can view a list of all the Objects, Purchases, etc., and where you can filter or search for more specific ones.&lt;br /&gt;
&lt;br /&gt;
* To view an item&#039;s details, simply click on its name.&lt;br /&gt;
* To search for a particular item, enter your search term in the search bar (top right) and click Enter.&lt;br /&gt;
* To filter the items by a particular property, click on the property you want to filter by on the right. If you don&#039;t see the property you want to filter by, click &#039;&#039;&#039;Show All&#039;&#039;&#039; and a list of all existing properties will be displayed.&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;br /&gt;
To access the Kiosk for checking items in our out, click on &#039;&#039;&#039;Home&#039;&#039;&#039; in the menu on the left. To check items in:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check in, one at a time.&lt;br /&gt;
* After you have scanned them all, click &#039;&#039;&#039;Check In&#039;&#039;&#039;.&lt;br /&gt;
* If the Check In button is grey-ed out, it means that some items have never been checked out. Click the red X next to their name to remove them from the list, and the Check In button will become active. See below for how to check items out.&lt;br /&gt;
&lt;br /&gt;
To check items out:&lt;br /&gt;
&lt;br /&gt;
* Select the textbox with the text &amp;quot;Enter barcodes here&amp;quot; by clicking inside it.&lt;br /&gt;
* Use a barcode scanner to scan the items you want to check out, one at a time.&lt;br /&gt;
* Scan the library card of an existing user whose library card is matched to their profile in the same way. See above for how to match a library card or add a new user.&lt;br /&gt;
* After you have scanned all items and a single library card, click &#039;&#039;&#039;Check Out&#039;&#039;&#039;.&lt;br /&gt;
* If the Check Out button is grey-ed out, it means that some items are still on loan and cannot be checked in. Click the red X next to their name to remove them from the list, and the Check Out button will become active. See above for how to check items in.&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5230</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5230"/>
		<updated>2010-11-16T23:51:18Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding a User or Matching a Profile to a Library Card */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
Click on an item in the menu on the left, such as &#039;&#039;&#039;Objects&#039;&#039;&#039;, &#039;&#039;&#039;Purchases&#039;&#039;&#039;, &#039;&#039;&#039;Categories&#039;&#039;&#039;, etc.. These links will bring you to a page where you can view a list of all the Objects, Purchases, etc., and where you can filter or search for more specific ones.&lt;br /&gt;
&lt;br /&gt;
* To view an item&#039;s details, simply click on its name.&lt;br /&gt;
* To search for a particular item, enter your search term in the search bar (top right) and click Enter.&lt;br /&gt;
* To filter the items by a particular property, click on the property you want to filter by on the right. If you don&#039;t see the property you want to filter by, click &#039;&#039;&#039;Show All&#039;&#039;&#039; and a list of all existing properties will be displayed.&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5229</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5229"/>
		<updated>2010-11-16T23:48:44Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Viewing, Filtering and Searching for Items */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
Click on an item in the menu on the left, such as &#039;&#039;&#039;Objects&#039;&#039;&#039;, &#039;&#039;&#039;Purchases&#039;&#039;&#039;, &#039;&#039;&#039;Categories&#039;&#039;&#039;, etc.. These links will bring you to a page where you can view a list of all the Objects, Purchases, etc., and where you can filter or search for more specific ones.&lt;br /&gt;
&lt;br /&gt;
* To view an item&#039;s details, simply click on its name.&lt;br /&gt;
* To search for a particular item, enter your search term in the search bar (top right) and click Enter.&lt;br /&gt;
* To filter the items by a particular property, click on the property you want to filter by on the right. If you don&#039;t see the property you want to filter by, click &#039;&#039;&#039;Show All&#039;&#039;&#039; and a list of all existing properties will be displayed.&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5226</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5226"/>
		<updated>2010-10-29T01:51:23Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding a User or Matching a Profile to a Library Card */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card bar-code and click Finish. Phone number is optional.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
There is also a second option for matching an existing profile to their library card:&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Start typing the persons&#039; name in the box labeled &amp;quot;Search for a profile...&amp;quot;.&lt;br /&gt;
* Select the profile you wish to match from the list that pops up. If no profiles are found, you must add the new user (see below). Click Continue once selected.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
Adding a completely new user requires an extra step and the actual presence of the user (their password is required): &lt;br /&gt;
&lt;br /&gt;
* In the navigation menu on the left, click on &#039;&#039;&#039;Add&#039;&#039;&#039; next to User. Alternatively, you could also browse to &#039;&#039;&#039;Users&#039;&#039;&#039; from the navigation menu on the left then click &#039;&#039;&#039;Add new or match existing profile to library card&#039;&#039;&#039;.&lt;br /&gt;
* Ask the new user to enter their Research user name and password in the required fields, then click Add &amp;amp; Continue.&lt;br /&gt;
* On the next screen, enter their library card bar-code and optionally their phone number. Click Finish.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5225</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5225"/>
		<updated>2010-10-29T01:41:53Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding a User or Matching a Profile to a Library Card */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card and click Finish. Phone number is optional.&lt;br /&gt;
* &#039;&#039;&#039;Note:&#039;&#039;&#039; Our bar-code scanners automatically add an enter after the 11 digits. This can mean that you will submit a form before you actually wish to! This will be fixed, but in the meanwhile the trick is to add bar-codes to forms last.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5224</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5224"/>
		<updated>2010-10-29T01:39:48Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding a User or Matching a Profile to a Library Card */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card. If you only see their name, follow these instructions for matching their profile to a library card:&lt;br /&gt;
&lt;br /&gt;
* Click on their name. You will be brought to the Profile Details screen.&lt;br /&gt;
* You will see the message: &amp;quot;No library card matched to this user. Match now.&amp;quot; Click on &#039;&#039;&#039;Match Now&#039;&#039;&#039;.&lt;br /&gt;
* Enter the person&#039;s library card and click Finish. Phone number is optional.&lt;br /&gt;
&lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5215</id>
		<title>RATS 2 Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=RATS_2_Documentation&amp;diff=5215"/>
		<updated>2010-10-27T00:29:21Z</updated>

		<summary type="html">&lt;p&gt;Hha13: Created page with &amp;#039;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated.   == Basics == To use R…&amp;#039;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page serves as documentation for how to use [http://rats.iat.sfu.ca RATS 2]. As bugs are fixed and new features are added, this page will be updated. &lt;br /&gt;
&lt;br /&gt;
== Basics ==&lt;br /&gt;
To use RATS 2, you need to log in with your Research account and password, and to have administrator privileges you must be part of the Research administration LDAP group. When you first log in to RATS 2, your RATS 2 profile is automatically created and paired with your Research account. Your RATS 2 profile will however be missing important data such as your SFU library card barcode. See below for how to match your profile with your library card.&lt;br /&gt;
&lt;br /&gt;
== Viewing, Filtering and Searching for Items ==&lt;br /&gt;
&lt;br /&gt;
== Adding a User or Matching a Profile to a Library Card ==&lt;br /&gt;
Click on &#039;&#039;&#039;User&#039;&#039;&#039; in the menu on the left. Here you will see a list of everyone who has previously logged in to RATS 2, meaning that their RATS 2 profile has been created. If you see a library card number underneath their name, this means that their profile has already been matched to a library card.&lt;br /&gt;
 &lt;br /&gt;
== Adding Objects == &lt;br /&gt;
&lt;br /&gt;
=== Information You Need ===&lt;br /&gt;
&lt;br /&gt;
=== Step-by-step ===&lt;br /&gt;
&lt;br /&gt;
== Checking Items In and Out ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=5214</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=5214"/>
		<updated>2010-10-26T21:39:13Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome. This is a wiki for the purpose of helping to keep the systems in Research running smoothly and to inform users of Research services.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
User Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Projects&#039;&#039;&#039;&lt;br /&gt;
* [[AG Node Documentation]]&lt;br /&gt;
* [[Eye trackers @ EC3 Lab]]&lt;br /&gt;
* [[Large Scale Imagery: evolving the components]]&lt;br /&gt;
* [[Cluster User Documentation|Documentation for the Cluster]]&lt;br /&gt;
* [[SGI]]&lt;br /&gt;
* [[Acoustic Panels - DIY]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Workstations&#039;&#039;&#039;&lt;br /&gt;
* [[Printers]]&lt;br /&gt;
* [[Research Workstations - default software loads | Standard Workstation Software List]]&lt;br /&gt;
* [[Windows Maintenance]]&lt;br /&gt;
* [[Linux Administration &amp;amp; Maintenance]]&lt;br /&gt;
* [[MAC Addresses and Hostnames]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;General Information&#039;&#039;&#039;&lt;br /&gt;
* [[Research Services]]&lt;br /&gt;
* [[Accessing Your Data]]&lt;br /&gt;
* [[People power - grad students and their expertise]]&lt;br /&gt;
* [[Research Mailing Lists]]&lt;br /&gt;
* [[HOWTO Access The SVN Server| Accessing the SVN Server]]&lt;br /&gt;
* [[HOWTO Access The CVS Server| Accessing the CVS Server]]&lt;br /&gt;
* [[Lockers]]&lt;br /&gt;
* [[Policies and Procedures]]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Administration Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Administration &amp;amp; Resource Management&#039;&#039;&#039;&lt;br /&gt;
* [[Research Administration Tasks]]&lt;br /&gt;
* [[Server documentation | Server List]]&lt;br /&gt;
* [[Network Devices Servers &amp;amp; Workstations]]&lt;br /&gt;
* [[Workstation Naming Convention]]&lt;br /&gt;
* [[Backups with AMANDA]]&lt;br /&gt;
* [[INFO Network Routing Information | Network Routing Information]]&lt;br /&gt;
* [[RAID Documentation]]&lt;br /&gt;
* [[Software Management]]&lt;br /&gt;
* [[Websites Hosted]]&lt;br /&gt;
* [[RATS 2 Documentation]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Customizing Linux Servers&#039;&#039;&#039;&lt;br /&gt;
* [[Research Servers - default software loads | Standard Server Software List]]&lt;br /&gt;
* [[REF Standard Server Configuration | Standard Server Configuration]]&lt;br /&gt;
* [[Setup a Project Wiki|Setup MediaWiki]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Oracle on Gentoo]]&lt;br /&gt;
* [[WebDAV Setup]]&lt;br /&gt;
* [[Virtual Servers]]&lt;br /&gt;
* [[LTSP]]&lt;br /&gt;
* [[NFS Version 4]]&lt;br /&gt;
* [[XFS Filesystem HOWTO]]&lt;br /&gt;
* [[Webapp-Config]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Client Side &amp;amp; Other Articles&#039;&#039;&#039;&lt;br /&gt;
* [[Linux Tips and Tools]]&lt;br /&gt;
* [[HOWTO Install SUSE with AutoYast|Install SUSE with AutoYast]]&lt;br /&gt;
* [[Who&#039;s Where - Availability of Research staff|Availability of Research Staff]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Adding a Mac to the Research Domain]]&lt;br /&gt;
* [[Enterprise Deployment for Windows]]&lt;br /&gt;
* [[Short diradm Documentation]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Reference&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Manuals&#039;&#039;&#039;&lt;br /&gt;
* [[File Servers]]&lt;br /&gt;
* [[Belkin F1DA116T KVM Switch]]&lt;br /&gt;
* [[D-Link DGS-3224TG Switches]]&lt;br /&gt;
* [[Printer Manuals|Printers]]&lt;br /&gt;
* [[Scanners]]&lt;br /&gt;
* [[Theaterette Information, Instruction, and Manuals]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Notes&#039;&#039;&#039;&lt;br /&gt;
* [[Command Syntax]]&lt;br /&gt;
* [[Micellaneous Notes]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
* [http://research.iat.sfu.ca/awstats.pl?config=infrastructure AWstats (wiki-traffic)]&lt;br /&gt;
* [[Media:Satellite_channels.pdf|Bell ExpressVu Channels]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[http://research.iat.sfu.ca/wiki/index.php?title=Special:Recentchanges&amp;amp;feed=rss http://research.iat.sfu.ca/wiki/images/b/b6/Rss.gif]&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5114</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5114"/>
		<updated>2010-05-26T07:57:04Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For multiple users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$username@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Maya&amp;diff=5101</id>
		<title>Maya</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Maya&amp;diff=5101"/>
		<updated>2010-04-10T02:16:25Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Intructions for Maya 2011 =&lt;br /&gt;
&lt;br /&gt;
Maya provided by Autodesk&lt;br /&gt;
&lt;br /&gt;
== License-Server Installation ==&lt;br /&gt;
&lt;br /&gt;
The license server (FLEXnet) was downloaded from the Autodesk Subscriptions website and installed (as an rpm). Use the following init.d script to make it run:&lt;br /&gt;
&lt;br /&gt;
 #!/sbin/runscript&lt;br /&gt;
 # Copyright 1999-2004 Gentoo Foundation&lt;br /&gt;
 # Distributed under the terms of the GNU General Public License v2&lt;br /&gt;
 # $Header: /var/cvsroot/gentoo-x86/app-admin/flexlm/files/flexlm-init,v 1.4 2006/09/26 04:10:49 eradicator Exp $&lt;br /&gt;
 &lt;br /&gt;
 depend() {&lt;br /&gt;
         need net&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 start() {&lt;br /&gt;
         ebegin &amp;quot;Starting flexnet lmgrd&amp;quot;&lt;br /&gt;
         su - ${LMUSER} -c &amp;quot;echo starting lmgrd &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         nohup su - ${LMUSER} -c &amp;quot;umask 022; /opt/flexnetserver/lmgrd -c &#039;${LMLICENSE}&#039; &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         su - ${LMUSER} -c &amp;quot;echo sleep 5 &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         sleep 5&lt;br /&gt;
         su - ${LMUSER} -c &amp;quot;echo lmdiag &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         su - ${LMUSER} -c &amp;quot;/opt/flexnetserver/lmdiag -n -c &#039;${LMLICENSE}&#039; &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         su - ${LMUSER} -c &amp;quot;echo exiting &amp;gt;&amp;gt; &#039;${LMLOG}&#039;&amp;quot;&lt;br /&gt;
         eend $?&lt;br /&gt;
 }&lt;br /&gt;
 &lt;br /&gt;
 stop() {&lt;br /&gt;
         ebegin &amp;quot;Stopping flexnet lmgrd&amp;quot;&lt;br /&gt;
         /opt/flexnetserver/lmdown -q -all -c &amp;quot;${LMLICENSE}&amp;quot;&lt;br /&gt;
         eend $?&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
And here&#039;s the conf.d for it:&lt;br /&gt;
&lt;br /&gt;
 # Logfile path: (NOTE: This must be uid/gid owned by the value of $LMUSER!)&lt;br /&gt;
 LMLOG=&amp;quot;/var/log/flexnet.log&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 # Run the lmgrd user as:&lt;br /&gt;
 LMUSER=&amp;quot;flexlm&amp;quot; &lt;br /&gt;
 &lt;br /&gt;
 # List all license files delimeted by a colon&lt;br /&gt;
 LMLICENSE=&amp;quot;/opt/flexnetserver/MAYA2011enlicense.lic&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Make sure you open port 2080 in the firewall, and also allow pings since Maya 2011 requires this.&lt;br /&gt;
&lt;br /&gt;
== Maya Client (Workstation) Installation ==&lt;br /&gt;
&lt;br /&gt;
When installing the software, make sure to select Network License, and enter &#039;&#039;&#039;bismarck.iat.sfu.ca&#039;&#039;&#039; for the server. You also need to modify the generated license file.&lt;br /&gt;
&lt;br /&gt;
The location of this license-file varies a bit, according to your OS:&lt;br /&gt;
* Mac: /var/flexlm/Maya.lic&lt;br /&gt;
* Windows: C:\flexlm\Maya.lic&lt;br /&gt;
* Linux, IRIX, etc: /var/flexlm/Maya.lic&lt;br /&gt;
&lt;br /&gt;
Open the file in a text-editor and modify it to look as such&lt;br /&gt;
 SERVER bismarck.iat.sfu.ca 0 2080&lt;br /&gt;
 USE_SERVER&lt;br /&gt;
&lt;br /&gt;
= Intructions for Maya 2008 =&lt;br /&gt;
&lt;br /&gt;
Maya provided by Alias&lt;br /&gt;
&lt;br /&gt;
Lmhostid is a unique number created for each computer by the lmhostid program provided by alias. This number is required for purchasing a license, and is also called: Hardware Info: System ID.&lt;br /&gt;
&lt;br /&gt;
== Purchasing Maya ==&lt;br /&gt;
Make sure you purchase the &#039;&#039;&#039;floating license version&#039;&#039;&#039;, this is the only version that can be floated through a flexlm server. Keep track of the Customer Location Code (CLC).&lt;br /&gt;
&lt;br /&gt;
== License ==&lt;br /&gt;
Fill out the license form and select floating here:&lt;br /&gt;
http://www.alias.com/spar/&lt;br /&gt;
&lt;br /&gt;
== Relocation ==&lt;br /&gt;
Relocation is required if you move the flexlm server to another machine, or you have a license file created with 1 hardwareID that you want to use on another server. Alias will provide you with a new license file if you fill in the relocation form:&lt;br /&gt;
http://www.alias.com/relocation&lt;br /&gt;
&lt;br /&gt;
== License-Server Installation ==&lt;br /&gt;
&lt;br /&gt;
Download pdr_LicenseServer10.80_linux.tar.gz which contains lmgrd and sgiawd, necessary executables for starting flexlm with an alias license.dat file.&lt;br /&gt;
&lt;br /&gt;
Download it from:&lt;br /&gt;
&lt;br /&gt;
musashi:/export/mirror/purchased-software/lin&lt;br /&gt;
&lt;br /&gt;
OR&lt;br /&gt;
&lt;br /&gt;
alias.com/glb/eng/community/downloads.jsp&lt;br /&gt;
&lt;br /&gt;
put the license.dat file in the /etc/flexlm directory. Edit the file and replace &#039;server&#039; with the actual server name.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note: Add this line to the license file to lock down the sgiawd service to a certain port:&lt;br /&gt;
VENDOR sgiawd port=****&lt;br /&gt;
&lt;br /&gt;
== Maya Client (Workstation) Installation ==&lt;br /&gt;
There are two steps to a workstation-installation:&lt;br /&gt;
*create the license-file on the client workstation, which will direct the workstation Maya client to &amp;quot;talk&amp;quot; to our flexlm server for authourization to run&lt;br /&gt;
*install the Maya software (currently version 7 - Jan. 2008)&lt;br /&gt;
&lt;br /&gt;
At this time of writing (Jan. 2008) we have 3 &amp;quot;Permanent&amp;quot; copies of Maya Unlimited, with Cloth, Fluids and Fur effects.&lt;br /&gt;
&lt;br /&gt;
=== Maya Client:  License File ===&lt;br /&gt;
The location of this license-file varies a bit, according to your OS:&lt;br /&gt;
* Mac: /var/flexlm/aw_client.dat&lt;br /&gt;
* Windows: C:\FLEXlm\aw_servername.dat&lt;br /&gt;
* Linux, IRIX, etc: /var/flexlm/aw_servername.dat&lt;br /&gt;
&lt;br /&gt;
Open a text-editor and create the license-file that points to our flexlm server.&lt;br /&gt;
For Windows, the file is:&lt;br /&gt;
 C:\FlexLm\aw_bismarck.dat&lt;br /&gt;
&lt;br /&gt;
The file must contain:&lt;br /&gt;
 SERVER bismarck.iat.sfu.ca 0 7111&lt;br /&gt;
 USE_SERVER&lt;br /&gt;
&lt;br /&gt;
=== Maya Client:  Software Installation ===&lt;br /&gt;
Grab the CD&#039;s, begin installing and follow your nose :-)&amp;lt;br&amp;gt;&lt;br /&gt;
After installing, with the license-file in place, it should &amp;quot;just work&amp;quot; :-)&lt;br /&gt;
&lt;br /&gt;
For server debug output:&lt;br /&gt;
 # tail -f /var/log/flexlm.log&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5090</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5090"/>
		<updated>2010-01-28T00:04:47Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a group */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5089</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5089"/>
		<updated>2010-01-28T00:04:39Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/projects/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5055</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5055"/>
		<updated>2009-10-30T01:44:17Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a gruop */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a group ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5054</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5054"/>
		<updated>2009-10-30T01:44:02Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a gruop ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to add an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5053</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5053"/>
		<updated>2009-10-30T01:41:36Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$user&#039;&#039;&#039; designates the user for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chown -R $user /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2701 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the user&#039;s home directory&lt;br /&gt;
* As root on whatever you want:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to an alias!&lt;br /&gt;
&lt;br /&gt;
=== For a gruop ===&lt;br /&gt;
&lt;br /&gt;
Note that &#039;&#039;&#039;$project&#039;&#039;&#039; designates the name of the new project and &#039;&#039;&#039;$group&#039;&#039;&#039; designates the group for whom the project is being created.&lt;br /&gt;
&lt;br /&gt;
First create a [[Research Administration Tasks#Adding Groups|new group]].&lt;br /&gt;
&lt;br /&gt;
Create the new project directory:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project&lt;br /&gt;
 # chgrp -R $group /mnt/raid/projects/$project&lt;br /&gt;
 # chmod -R 2771 /mnt/raid/projects/$project&lt;br /&gt;
 # mkdir /mnt/raid/projects/$project/htdocs&lt;br /&gt;
 # chmod 2775 /mnt/raid/projects/$project/htdocs&lt;br /&gt;
&lt;br /&gt;
Add an LDAP entry for the newly created project:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O home.projects $project 209.87.56.231:/mnt/raid/projects/$project&lt;br /&gt;
# &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
&lt;br /&gt;
Create a sym-link in the all the user&#039;s home directories (the users belonging to $group). To find out who is in what group, use the command getent group | grep $group on any ldap-enabled machine.&lt;br /&gt;
* As root on your LDAP-enabled machine of choice:&lt;br /&gt;
 # cd /home/users/$user&lt;br /&gt;
 # ln -s /home/projects/$project&lt;br /&gt;
&lt;br /&gt;
Next, to set the up the hosting and the database:&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules00&#039;&#039;&#039; set up a new vhost.conf using an existing template:&lt;br /&gt;
 # cd /etc/apache2/vhosts.d/&lt;br /&gt;
 # cat vhost_template.sample &amp;gt; $project.conf&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TO DO - DATABASE HOWTO&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Make sure you get Vic to an alias!&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5052</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=5052"/>
		<updated>2009-10-30T01:10:22Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* An email will be sent to their email address&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
* &#039;&#039;&#039;Add the new user to &#039;/etc/amanda/spitfire/disklist&#039;.  This is to enable backups of the user&#039;s home directory &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
* Comment out the user from /etc/amanda/spitfire/disklist, only if they will never need the data.&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2700 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R root:$group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Servers:Hercules&amp;diff=5051</id>
		<title>Servers:Hercules</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Servers:Hercules&amp;diff=5051"/>
		<updated>2009-10-20T22:49:19Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding a new vserver ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;:&lt;br /&gt;
* First create the template the server will use for portage &lt;br /&gt;
 # cd /etc/managed-portage/&lt;br /&gt;
 # rsync -avP hosts/TEMPLATE_webdb/ hosts/sr-hercules$$&lt;br /&gt;
* Commit the new vserver&#039;s template to git&lt;br /&gt;
 # git add /hosts/sr-hercules$$&lt;br /&gt;
 # git commit -m &#039;New VM, Hercules$$&#039;&lt;br /&gt;
 # git push&lt;br /&gt;
* Create the new vserver&lt;br /&gt;
 # cd ~/vps-siat/scripts/&lt;br /&gt;
 # ./make-vps sr-hercules$$ br0:10.0.1.XX/16 br0:209.87.56.XX/24&lt;br /&gt;
* Note that $$ must be the number of the new vserver, which start at 00.&lt;br /&gt;
* Further note that XX is the IP to be assigned to the new server. &#039;&#039;&#039;Be very careful not to assign an already taken IP.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Removing an existing vserver ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;: &lt;br /&gt;
* First ensure that the Vserver is stopped&lt;br /&gt;
 # vserver sr-hercules$$ stop&lt;br /&gt;
* Kill the server&lt;br /&gt;
 # cd ~/vps-siat/scripts/&lt;br /&gt;
 # ./kill-vps sr-hercules$$&lt;br /&gt;
* Note that $$ must be the number of the vserver.&lt;br /&gt;
&lt;br /&gt;
== Working with managed-portage profiles ==&lt;br /&gt;
* &#039;&#039;&#039;It is very important that you DO NOT touch /etc/portage/ on any vserver.&#039;&#039;&#039; Everything must be done through /etc/managed-portage/ on the master server.&lt;br /&gt;
* Below are a few common tasks for managed-portage&lt;br /&gt;
=== Setting up vserver-specific USE flags ===&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;:&lt;br /&gt;
 # cd /etc/managed-portage/hosts/sr-hercules$$/make.profile/&lt;br /&gt;
* Here you can create/edit any regular files you would under /etc/portage/, such as package.use for example:&lt;br /&gt;
 # vim package.use&lt;br /&gt;
* Specify what USE flags you&#039;d like a package to use&lt;br /&gt;
* Commit the changes to git&lt;br /&gt;
 # git commit -m &#039;$MESSAGE&#039; package.use&lt;br /&gt;
 # git push&lt;br /&gt;
 # cd /vservers/sr-hercules$$/etc/managed-portage/&lt;br /&gt;
 # git pull&lt;br /&gt;
* Note that $$ must be the number of the new vserver, which start at 00.&lt;br /&gt;
* Also note that you must replace package.use with whatever file you edited/created.&lt;br /&gt;
=== Changing or setting the profile of a vserver ===&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;:&lt;br /&gt;
 # cd /etc/managed-portage/class/$PROFILE&lt;br /&gt;
* Add the name of the vserver to the applies_to file (if your vserver is sr-hercules99, add &#039;sr-hercules99&#039; to a new line in the file)&lt;br /&gt;
* Commit the changes to git&lt;br /&gt;
 # git commit -m &amp;quot;$MESSAGE&#039; applies_to&lt;br /&gt;
 # git push&lt;br /&gt;
* Enter the vserver&lt;br /&gt;
 # vserver sr-hercules$$ enter&lt;br /&gt;
* Pull the changes from git and emerge&lt;br /&gt;
 # cd /etc/managed-portage/&lt;br /&gt;
 # git pull&lt;br /&gt;
 # emerge -knN @system ; emerge -knN @world ; emerge -knN @installed&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Servers:Hercules&amp;diff=5050</id>
		<title>Servers:Hercules</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Servers:Hercules&amp;diff=5050"/>
		<updated>2009-10-20T22:35:40Z</updated>

		<summary type="html">&lt;p&gt;Hha13: New page: == Adding a new vserver == * As root on &amp;#039;&amp;#039;&amp;#039;hercules&amp;#039;&amp;#039;&amp;#039;: * First create the template the server will use for portage   # cd /etc/managed-portage/  # rsync -avP hosts/TEMPLATE_webdb/ hosts/s...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding a new vserver ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;:&lt;br /&gt;
* First create the template the server will use for portage &lt;br /&gt;
 # cd /etc/managed-portage/&lt;br /&gt;
 # rsync -avP hosts/TEMPLATE_webdb/ hosts/sr-hercules$$&lt;br /&gt;
* Commit the new vserver&#039;s template to git&lt;br /&gt;
 # git add /hosts/sr-hercules$$&lt;br /&gt;
 # git commit -m &#039;New VM, Hercules$$&#039;&lt;br /&gt;
 # git push&lt;br /&gt;
* Create the new vserver&lt;br /&gt;
 # cd ~/vps-siat/scripts/&lt;br /&gt;
 # ./make-vps sr-hercules$$ br0:10.0.1.XX/16 br0:209.87.56.XX/24&lt;br /&gt;
* Note that $$ must be the number of the new vserver, which start at 00.&lt;br /&gt;
* Further note that XX is the IP to be assigned to the new server. &#039;&#039;&#039;Be very careful not to assign an already taken IP.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Removing an existing vserver ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hercules&#039;&#039;&#039;: &lt;br /&gt;
* First ensure that the Vserver is stopped&lt;br /&gt;
 # vserver sr-hercules$$ stop&lt;br /&gt;
* Kill the server&lt;br /&gt;
 # cd ~/vps-siat/scripts/&lt;br /&gt;
 # ./kill-vps sr-hercules$$&lt;br /&gt;
* Note that $$ must be the number of the vserver.&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4852</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4852"/>
		<updated>2009-01-15T21:00:02Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Deleting Users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4850</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4850"/>
		<updated>2009-01-13T22:42:19Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding CVS Repositories */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the CVS repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the cvs group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user cvs&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /mnt/raid/cvs/$repository&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/cvs/$repository&lt;br /&gt;
 # chgrp -R $group /mnt/raid/cvs/$repository&lt;br /&gt;
&lt;br /&gt;
* To access the CVS repository, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* See the more detailed [[HOWTO_Access_The_CVS_Server | CVS User guide]]&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=HOWTO_Access_The_CVS_Server&amp;diff=4849</id>
		<title>HOWTO Access The CVS Server</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=HOWTO_Access_The_CVS_Server&amp;diff=4849"/>
		<updated>2009-01-09T22:46:15Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For those who don&#039;t like to read, here is the information you&#039;ll need (replace $user with your username and $repository with your repository name):&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Use CVS_RSH=&amp;quot;ssh&amp;quot; with the URL being :ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Command Line on Linux ==&lt;br /&gt;
Checkout&lt;br /&gt;
 # export CVSROOT=:ext:username@cvs.iat.sfu.ca:/var/cvsroot/projectname&lt;br /&gt;
 # export CVS_RSH=ssh&lt;br /&gt;
 # cvs checkout modulename&lt;br /&gt;
Update&lt;br /&gt;
 # cvs update modulename&lt;br /&gt;
&lt;br /&gt;
== Eclipse on Windows ==&lt;br /&gt;
&lt;br /&gt;
To checkout a repository with Eclipse, use the Import Project tool from CVS. Enter the information below with Your projectname, and Your username/password&lt;br /&gt;
&lt;br /&gt;
[[Image:eclipse-cvs-checkout.gif]]&lt;br /&gt;
&lt;br /&gt;
Then, select Use an existing module to see a list of which modules you can checkout (they will be listed below).&lt;br /&gt;
&lt;br /&gt;
[[Image:eclipse-cvs-checkout-module.gif]]&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Linux_Tips_and_Tools&amp;diff=4846</id>
		<title>Linux Tips and Tools</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Linux_Tips_and_Tools&amp;diff=4846"/>
		<updated>2009-01-08T23:36:50Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Automatic (Pronounceable) Password Generation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Automatic (Pronounceable) Password Generation==&lt;br /&gt;
Use of automated tools will help ensure high-quality passwords, enhancing security.  &#039;&#039;&#039;apg&#039;&#039;&#039; is one such tool, which (by default) attempts to generate pronounceable passwords.&lt;br /&gt;
Once &#039;&#039;&#039;apg&#039;&#039;&#039; is installed, invoking it like this will produce best results:&lt;br /&gt;
 &amp;lt;font color=red&amp;gt;hostname&amp;lt;/font&amp;gt; &amp;lt;font color=blue&amp;gt;~ #&amp;lt;/font&amp;gt; &#039;&#039;&#039;/usr/bin/apg -M NCL -t -m 9 -x 9 -n 10 -E O | egrep -v [ol]&#039;&#039;&#039;&lt;br /&gt;
Explanation of options:&lt;br /&gt;
*&#039;&#039;&#039;-M&#039;&#039;&#039; is a mode-switch, with following options which tell &#039;&#039;&#039;apg&#039;&#039;&#039; what characterset to use&lt;br /&gt;
**&#039;&#039;&#039;-N&#039;&#039;&#039; numbers must be included with each password&lt;br /&gt;
**&#039;&#039;&#039;-C&#039;&#039;&#039; upper-case (capital) letters must be included&lt;br /&gt;
**&#039;&#039;&#039;-L&#039;&#039;&#039; lower-case letters must be included&lt;br /&gt;
*&#039;&#039;&#039;-m 9&#039;&#039;&#039; minimum password length&lt;br /&gt;
*&#039;&#039;&#039;-x 9&#039;&#039;&#039; maximum password length&lt;br /&gt;
*&#039;&#039;&#039;-n 10&#039;&#039;&#039; generate 10 passwords  After the &#039;&#039;&#039;egrep&#039;&#039;&#039; filtering below, you will get substantially fewer than 10 results.&lt;br /&gt;
*&#039;&#039;&#039;-E O&#039;&#039;&#039; exclude letters (upper-case only possible) O from password.  This prevents confusion with &amp;quot;oh&amp;quot; and &amp;quot;zero&amp;quot;.&lt;br /&gt;
*&#039;&#039;&#039;| egrep -v [ol]&#039;&#039;&#039; does the same as above, except it filters out/discards passwords with lower-case ol.  This prevents confusion with &amp;quot;oh&amp;quot; and &amp;quot;zero&amp;quot;; &amp;quot;ell&amp;quot; and &amp;quot;one&amp;quot;.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Screen ==&lt;br /&gt;
Screen is a very powerful terminal application that makes server and remote maintenance much easier.&lt;br /&gt;
&lt;br /&gt;
Screen sessions can be created, detached, and then later resumed from another machine. This allows you to ssh to a machine, start a compile or emerge, detach and logout, and then come back later to the session and see it finished.&lt;br /&gt;
&lt;br /&gt;
Screen session are created from the terminal with&lt;br /&gt;
 &amp;lt;font color=blue&amp;gt;#&amp;lt;/font&amp;gt; screen&lt;br /&gt;
&lt;br /&gt;
A session is detached by a Ctrl-a d.&lt;br /&gt;
&lt;br /&gt;
There are three more commands you should know:&lt;br /&gt;
 &amp;lt;font color=blue&amp;gt;#&amp;lt;/font&amp;gt; screen -r&lt;br /&gt;
 &amp;lt;font color=blue&amp;gt;#&amp;lt;/font&amp;gt; screen -ls&lt;br /&gt;
 &amp;lt;font color=blue&amp;gt;#&amp;lt;/font&amp;gt; screen -r ####&lt;br /&gt;
The first to reattach a session, and the second to list the screen sessions. The third is useful if there is more than one screen sessions you can reattach. Just list the sessions and then reattach with the specific numbers given for the session you want.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Genlop ==&lt;br /&gt;
{{Gentoo}}&lt;br /&gt;
Genlop is a log reporting program for gentoo&#039;s portage utility. Want to know how much longer the package being emerged will take? or average emerge time? This program has it all&lt;br /&gt;
 # emerge genlop&lt;br /&gt;
&lt;br /&gt;
Here&#039;s how to use it. First is emerge history, second is information on the current package being emerged + expected time remaining, third is for averge build time of that package.&lt;br /&gt;
 # genlop -l&lt;br /&gt;
 # genlop -c&lt;br /&gt;
 # genlop -i gcc&lt;br /&gt;
&lt;br /&gt;
== Colourize Grep ==&lt;br /&gt;
Add this to your &#039;&#039;&#039;.bashrc&#039;&#039;&#039; file.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
if echo hello|grep --color=auto l &amp;gt;/dev/null 2&amp;gt;&amp;amp;1; then&lt;br /&gt;
  export GREP_OPTIONS=&#039;--color=auto&#039; GREP_COLOR=&#039;1;32&#039;&lt;br /&gt;
fi&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4844</id>
		<title>Setup a Project Wiki</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4844"/>
		<updated>2009-01-07T23:54:46Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Upgrade MediaWiki */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4843</id>
		<title>Setup a Project Wiki</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4843"/>
		<updated>2009-01-07T23:53:41Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* = */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4842</id>
		<title>Setup a Project Wiki</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4842"/>
		<updated>2009-01-07T23:53:30Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* = */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4841</id>
		<title>Websites Hosted</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4841"/>
		<updated>2009-01-07T22:45:04Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* List of hosted domains */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== List of hosted domains ==&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer00 ===&lt;br /&gt;
* http://meatbook.iat.sfu.ca&lt;br /&gt;
* http://pain.iat.sfu.ca&lt;br /&gt;
* http://www.transformingpain.org&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer01 ===&lt;br /&gt;
* http://lore.iat.sfu.ca&lt;br /&gt;
* http://lornet.iat.sfu.ca&lt;br /&gt;
* http://ecl.iat.sfu.ca&lt;br /&gt;
* http://stories.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer02 ===&lt;br /&gt;
* http://www.antle.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer03 ===&lt;br /&gt;
* http://dolphin.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer04 ===&lt;br /&gt;
* http://www.mmart.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-vindicator00 ===&lt;br /&gt;
* http://mapture.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-vindicator01 ===&lt;br /&gt;
* http://catgames.ca&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4840</id>
		<title>Websites Hosted</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4840"/>
		<updated>2009-01-07T22:12:42Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* List of hosted domains */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== List of hosted domains ==&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer01 ===&lt;br /&gt;
* http://lore.iat.sfu.ca&lt;br /&gt;
* http://lornet.iat.sfu.ca&lt;br /&gt;
* http://ecl.iat.sfu.ca&lt;br /&gt;
* http://stories.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer02 ===&lt;br /&gt;
* http://www.antle.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer03 ===&lt;br /&gt;
* http://dolphin.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer04 ===&lt;br /&gt;
* http://www.mmart.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-vindicator00 ===&lt;br /&gt;
* http://mapture.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-vindicator01 ===&lt;br /&gt;
* http://catgames.ca&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4839</id>
		<title>Websites Hosted</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Websites_Hosted&amp;diff=4839"/>
		<updated>2009-01-07T22:10:48Z</updated>

		<summary type="html">&lt;p&gt;Hha13: New page: == List of hosted domains ==  === sr-skimmer01 === * http://lore.iat.sfu.ca * http://lornet.iat.sfu.ca * http://ecl.iat.sfu.ca * http://stories.iat.sfu.ca  === sr-skimmer02 === * http://ww...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== List of hosted domains ==&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer01 ===&lt;br /&gt;
* http://lore.iat.sfu.ca&lt;br /&gt;
* http://lornet.iat.sfu.ca&lt;br /&gt;
* http://ecl.iat.sfu.ca&lt;br /&gt;
* http://stories.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer02 ===&lt;br /&gt;
* http://www.antle.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer03 ===&lt;br /&gt;
* http://dolphin.iat.sfu.ca&lt;br /&gt;
&lt;br /&gt;
=== sr-skimmer04 ===&lt;br /&gt;
* http://www.mmart.iat.sfu.ca&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=4838</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=4838"/>
		<updated>2009-01-07T21:59:39Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome. This is a wiki for the purpose of helping to keep the systems in Research running smoothly and to inform users of Research services.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
User Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Projects&#039;&#039;&#039;&lt;br /&gt;
* [[AG Node Documentation]]&lt;br /&gt;
* [[Eye trackers @ EC3 Lab]]&lt;br /&gt;
* [[Large Scale Imagery: evolving the components]]&lt;br /&gt;
* [[Cluster User Documentation|Documentation for the Cluster]]&lt;br /&gt;
* [[SGI]]&lt;br /&gt;
* [[Acoustic Panels - DIY]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Workstations&#039;&#039;&#039;&lt;br /&gt;
* [[Printers]]&lt;br /&gt;
* [[Research Workstations - default software loads | Standard Workstation Software List]]&lt;br /&gt;
* [[Windows Maintenance]]&lt;br /&gt;
* [[Linux Administration &amp;amp; Maintenance]]&lt;br /&gt;
* [[MAC Addresses and Hostnames]]&lt;br /&gt;
* [[Problems due to moving]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;General Information&#039;&#039;&#039;&lt;br /&gt;
* [[Research Services]]&lt;br /&gt;
* [[Accessing Your Data]]&lt;br /&gt;
* [[People power - grad students and their expertise]]&lt;br /&gt;
* [[Research Mailing Lists]]&lt;br /&gt;
* [[HOWTO Access The SVN Server| Accessing the SVN Server]]&lt;br /&gt;
* [[HOWTO Access The CVS Server| Accessing the CVS Server]]&lt;br /&gt;
* [[Lockers]]&lt;br /&gt;
* [[Policies and Procedures]]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Administration Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Administration &amp;amp; Resource Management&#039;&#039;&#039;&lt;br /&gt;
* [[Research Administration Tasks]]&lt;br /&gt;
* [[Server documentation | Server List]]&lt;br /&gt;
* [[Network Devices Servers &amp;amp; Workstations]]&lt;br /&gt;
* [[Workstation Naming Convention]]&lt;br /&gt;
* [[Backups with AMANDA]]&lt;br /&gt;
* [[INFO Network Routing Information | Network Routing Information]]&lt;br /&gt;
* [[RAID Documentation]]&lt;br /&gt;
* [[Software Management]]&lt;br /&gt;
* [[Websites Hosted]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Customizing Linux Servers&#039;&#039;&#039;&lt;br /&gt;
* [[Research Servers - default software loads | Standard Server Software List]]&lt;br /&gt;
* [[REF Standard Server Configuration | Standard Server Configuration]]&lt;br /&gt;
* [[Setup a Project Wiki|Setup MediaWiki]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Oracle on Gentoo]]&lt;br /&gt;
* [[WebDAV Setup]]&lt;br /&gt;
* [[Virtual Servers]]&lt;br /&gt;
* [[LTSP]]&lt;br /&gt;
* [[NFS Version 4]]&lt;br /&gt;
* [[XFS Filesystem HOWTO]]&lt;br /&gt;
* [[Webapp-Config]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Client Side &amp;amp; Other Articles&#039;&#039;&#039;&lt;br /&gt;
* [[Linux Tips and Tools]]&lt;br /&gt;
* [[HOWTO Install SUSE with AutoYast|Install SUSE with AutoYast]]&lt;br /&gt;
* [[Who&#039;s Where - Availability of Research staff|Availability of Research Staff]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Adding a Mac to the Research Domain]]&lt;br /&gt;
* [[Windows XP Maintenance]]&lt;br /&gt;
* [[Short diradm Documentation]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Reference&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Manuals&#039;&#039;&#039;&lt;br /&gt;
* [[File Servers]]&lt;br /&gt;
* [[Belkin F1DA116T KVM Switch]]&lt;br /&gt;
* [[D-Link DGS-3224TG Switches]]&lt;br /&gt;
* [[Printer Manuals|Printers]]&lt;br /&gt;
* [[Theaterette Information, Instruction, and Manuals]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Notes&#039;&#039;&#039;&lt;br /&gt;
* [[Command Syntax]]&lt;br /&gt;
* [[Micellaneous Notes]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
* [http://research.iat.sfu.ca/awstats.pl?config=infrastructure AWstats (wiki-traffic)]&lt;br /&gt;
* [[Media:Satellite_channels.pdf|Bell ExpressVu Channels]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[http://research.iat.sfu.ca/wiki/index.php?title=Special:Recentchanges&amp;amp;feed=rss http://research.iat.sfu.ca/images/rss.gif]&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4836</id>
		<title>Setup a Project Wiki</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4836"/>
		<updated>2009-01-06T22:26:48Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Add a Separate Instance of MediaWiki */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4835</id>
		<title>Setup a Project Wiki</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Setup_a_Project_Wiki&amp;diff=4835"/>
		<updated>2009-01-06T22:26:31Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Add a Separate Instance of MediaWiki */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Short_diradm_Documentation&amp;diff=4823</id>
		<title>Short diradm Documentation</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Short_diradm_Documentation&amp;diff=4823"/>
		<updated>2008-12-07T00:03:39Z</updated>

		<summary type="html">&lt;p&gt;Hha13: New page: Make sure the diradm.conf file has the following settings on spitfire:   SAMBAPATHPREPEND=&amp;#039;\\\SPITFIRE\Users&amp;#039;  AUTOMOUNT_HASHING=&amp;#039;${key}&amp;#039; # no home directory hashing   AUTOMOUNT_USERDIRBAS...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Make sure the diradm.conf file has the following settings on spitfire:&lt;br /&gt;
&lt;br /&gt;
 SAMBAPATHPREPEND=&#039;\\\SPITFIRE\Users&#039;&lt;br /&gt;
 AUTOMOUNT_HASHING=&#039;${key}&#039; # no home directory hashing &lt;br /&gt;
 AUTOMOUNT_USERDIRBASE=&amp;quot;209.87.56.230:/home/users&amp;quot;&lt;br /&gt;
 AUTOMOUNT_GROUPDIRBASE=&amp;quot;209.87.56.230:/home/projects&amp;quot;&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=4822</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Main_Page&amp;diff=4822"/>
		<updated>2008-12-06T23:54:46Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome. This is a wiki for the purpose of helping to keep the systems in Research running smoothly and to inform users of Research services.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
User Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Projects&#039;&#039;&#039;&lt;br /&gt;
* [[AG Node Documentation]]&lt;br /&gt;
* [[Eye trackers @ EC3 Lab]]&lt;br /&gt;
* [[Large Scale Imagery: evolving the components]]&lt;br /&gt;
* [[Cluster User Documentation|Documentation for the Cluster]]&lt;br /&gt;
* [[SGI]]&lt;br /&gt;
* [[Acoustic Panels - DIY]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Workstations&#039;&#039;&#039;&lt;br /&gt;
* [[Printers]]&lt;br /&gt;
* [[Research Workstations - default software loads | Standard Workstation Software List]]&lt;br /&gt;
* [[Windows Maintenance]]&lt;br /&gt;
* [[Linux Administration &amp;amp; Maintenance]]&lt;br /&gt;
* [[MAC Addresses and Hostnames]]&lt;br /&gt;
* [[Problems due to moving]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;General Information&#039;&#039;&#039;&lt;br /&gt;
* [[Research Services]]&lt;br /&gt;
* [[Accessing Your Data]]&lt;br /&gt;
* [[People power - grad students and their expertise]]&lt;br /&gt;
* [[Research Mailing Lists]]&lt;br /&gt;
* [[HOWTO Access The SVN Server| Accessing the SVN Server]]&lt;br /&gt;
* [[HOWTO Access The CVS Server| Accessing the CVS Server]]&lt;br /&gt;
* [[Lockers]]&lt;br /&gt;
* [[Policies and Procedures]]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Administration Articles&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Administration &amp;amp; Resource Management&#039;&#039;&#039;&lt;br /&gt;
* [[Research Administration Tasks]]&lt;br /&gt;
* [[Server documentation | Server List]]&lt;br /&gt;
* [[Network Devices Servers &amp;amp; Workstations]]&lt;br /&gt;
* [[Workstation Naming Convention]]&lt;br /&gt;
* [[Backups with AMANDA]]&lt;br /&gt;
* [[INFO Network Routing Information | Network Routing Information]]&lt;br /&gt;
* [[RAID Documentation]]&lt;br /&gt;
* [[Software Management]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Customizing Linux Servers&#039;&#039;&#039;&lt;br /&gt;
* [[Research Servers - default software loads | Standard Server Software List]]&lt;br /&gt;
* [[REF Standard Server Configuration | Standard Server Configuration]]&lt;br /&gt;
* [[Setup a Project Wiki|Setup MediaWiki]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Oracle on Gentoo]]&lt;br /&gt;
* [[WebDAV Setup]]&lt;br /&gt;
* [[Virtual Servers]]&lt;br /&gt;
* [[LTSP]]&lt;br /&gt;
* [[NFS Version 4]]&lt;br /&gt;
* [[XFS Filesystem HOWTO]]&lt;br /&gt;
* [[Webapp-Config]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Client Side &amp;amp; Other Articles&#039;&#039;&#039;&lt;br /&gt;
* [[Linux Tips and Tools]]&lt;br /&gt;
* [[HOWTO Install SUSE with AutoYast|Install SUSE with AutoYast]]&lt;br /&gt;
* [[Who&#039;s Where - Availability of Research staff|Availability of Research Staff]]&lt;br /&gt;
* [[Maya]]&lt;br /&gt;
* [[Adding a Mac to the Research Domain]]&lt;br /&gt;
* [[Windows XP Maintenance]]&lt;br /&gt;
* [[Short diradm Documentation]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;6&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: black solid 1px; border-collapse: collapse; text-align: left; width: 100%; background: #f0f0ff; &amp;quot;&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; style=&amp;quot;text-align: center; font-weight: bold; font-size: 1.4em;&amp;quot; |&lt;br /&gt;
Reference&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Manuals&#039;&#039;&#039;&lt;br /&gt;
* [[File Servers]]&lt;br /&gt;
* [[Belkin F1DA116T KVM Switch]]&lt;br /&gt;
* [[D-Link DGS-3224TG Switches]]&lt;br /&gt;
* [[Printer Manuals|Printers]]&lt;br /&gt;
* [[Theaterette Information, Instruction, and Manuals]]&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; | &#039;&#039;&#039;Notes&#039;&#039;&#039;&lt;br /&gt;
* [[Command Syntax]]&lt;br /&gt;
* [[Micellaneous Notes]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| width=&amp;quot;33%&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
* [http://research.iat.sfu.ca/awstats.pl?config=infrastructure AWstats (wiki-traffic)]&lt;br /&gt;
* [[Media:Satellite_channels.pdf|Bell ExpressVu Channels]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[http://research.iat.sfu.ca/wiki/index.php?title=Special:Recentchanges&amp;amp;feed=rss http://research.iat.sfu.ca/images/rss.gif]&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4821</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4821"/>
		<updated>2008-12-06T23:26:48Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Removing Key-served Applications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
This is very easy. Once you open up KeyConfigure, select the Application you&#039;d like to remove, and go to Edit &amp;gt; Delete (or click Cmd+delete on a Mac, or Delete on Windows).&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4820</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4820"/>
		<updated>2008-12-06T23:22:42Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Key-served Applications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4819</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4819"/>
		<updated>2008-12-06T23:07:25Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Key-served Applications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
===== Mac OS X ===== &lt;br /&gt;
&lt;br /&gt;
Before starting, you must be on a Mac or Windows PC that already has the software you&#039;d like to add installed and working.&lt;br /&gt;
&lt;br /&gt;
Open KeyConfigure and go to File &amp;gt; Create License (or press Cmd+i on a Mac or Ctrl+i on Windows). A new window will appear. Enter a License Name, usually the same as the Software name. Then click Browse, and find the App that you&#039;d like to keyserve (on a Mac it&#039;s usually under Applications, on Windows in Program Files). Double click it.&lt;br /&gt;
&lt;br /&gt;
Make sure you check off &#039;Allow launch when KeyServer not available&#039; (this is the default) just in case something breaks on the server, so people can still use their software until it&#039;s fixed.&lt;br /&gt;
&lt;br /&gt;
Click OK. A new window with more details will come up. Expand the &#039;Limits&#039; section by clicking on the small triangle, and choose &#039;Concurrent Use Limit (Floating License)&#039;, and under &#039;User Limit&#039; enter the amount of licenses we own. Close the window, and make sure you &#039;Save&#039;.&lt;br /&gt;
&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4818</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4818"/>
		<updated>2008-12-06T21:19:57Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Viewing Key-served Applications */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
Open up K2&#039;s KeyConfigure, the license administration software. When you do, you&#039;ll need to enter the following information:&lt;br /&gt;
&lt;br /&gt;
* Server: research-keyserver.iat.sfu.ca&lt;br /&gt;
* Username: Administrator&lt;br /&gt;
* Password: secret&lt;br /&gt;
&lt;br /&gt;
Once open, you can see which Computers on the network are using what Software, what Software is running on what machine, and what Licenses are registered with the system.&lt;br /&gt;
&lt;br /&gt;
In the Licenses window, you will see the name of the application, as well as how many licenses are in use at that particular moment in time, how many people are waiting for a license to free up, and how many licenses we own (labeled as &#039;Limit&#039;).&lt;br /&gt;
&lt;br /&gt;
Double clicking on the name of a key-served software application, will bring up more details about its use. You can change the name of the application or change the way it is being key-served. More importantly, you can see who is using the application and on what machine (Click on &#039;Current User List&#039; or &#039;Computer List&#039;), and you can also see what application and which version is registered with the particular license. To see this, expand the &#039;Programs&#039; section.&lt;br /&gt;
&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4804</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4804"/>
		<updated>2008-11-28T22:06:02Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* Further note that $username is the new user&#039;s username (which will not be tied in with their regular SFU username), $email is their preferred email address and $fullname is their first and last name.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4803</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4803"/>
		<updated>2008-11-28T22:04:23Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For a single user */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4802</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4802"/>
		<updated>2008-11-28T22:04:09Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* For multiple users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4801</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4801"/>
		<updated>2008-11-28T22:03:57Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Dumping the contents of SVN Repositories to a file, and vice-versa */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;:&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4800</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4800"/>
		<updated>2008-11-28T22:03:42Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Working with LDAP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4799</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4799"/>
		<updated>2008-11-28T22:03:09Z</updated>

		<summary type="html">&lt;p&gt;Hha13: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;br /&gt;
&lt;br /&gt;
== Working with LDAP ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 dn: uid=bob,ou=Users,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
 changetype: modify&lt;br /&gt;
 replace: sambaHomePath&lt;br /&gt;
 sambaHomePath: \\NEW\Samba\home\path&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # ldapmodify -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;br /&gt;
&lt;br /&gt;
=== Deleting an LDAP entry ===&lt;br /&gt;
&lt;br /&gt;
Note that it is still better to delete users using the [[Research Administration Tasks#Deleting Users | diradm method above]], this is just for general use.&lt;br /&gt;
&lt;br /&gt;
First create a .ldif file with its content in this format:&lt;br /&gt;
&lt;br /&gt;
 cn=bob,ou=home.users,ou=AutoFS,dc=iat,dc=sfu,dc=ca&lt;br /&gt;
&lt;br /&gt;
Then run this command:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # ldapdelete -x -f $file.ldif -D cn=Manager,dc=iat,dc=sfu,dc=ca -W&lt;br /&gt;
* You will be prompted for our LDAP password&lt;br /&gt;
&lt;br /&gt;
The options in this command do the following:&lt;br /&gt;
* -x: use simple authentication instead of SASL&lt;br /&gt;
* -f: use the file $file.ldif to read the changes to be made&lt;br /&gt;
* -D: bind-dn (user to bind with)&lt;br /&gt;
* -W: prompt for password&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
	<entry>
		<id>https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4798</id>
		<title>Research Administration Tasks</title>
		<link rel="alternate" type="text/html" href="https://research.iat.sfu.ca/research/index.php?title=Research_Administration_Tasks&amp;diff=4798"/>
		<updated>2008-11-28T21:35:12Z</updated>

		<summary type="html">&lt;p&gt;Hha13: /* Adding Users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Adding Users ==&lt;br /&gt;
* As root on &#039;&#039;&#039;spitfire&#039;&#039;&#039;: &lt;br /&gt;
 # cd&lt;br /&gt;
 # DEBUG=1 /usr/local/sbin/diradm.superadduser &#039;$username&#039; &#039;$email&#039; &#039;$fullname&#039;&lt;br /&gt;
* Note that a file named &#039;$username&#039; is created in your current directory with the template filled out for mailing (the same file is displayed onscreen), and this is why it is very important to &#039;cd&#039; to root&#039;s home directory before running the script so as to not cause any problems with home-directory creation.&lt;br /&gt;
* The password you are prompted for at the end is for &#039;&#039;&#039;phaeton&#039;&#039;&#039;.&lt;br /&gt;
* Add the newly-created user to our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List].&lt;br /&gt;
&lt;br /&gt;
== Deleting Users ==&lt;br /&gt;
Make sure there are no sym-links pointing to important stuff!!&lt;br /&gt;
 # find -P /home/users/$username -noleaf  -type l&lt;br /&gt;
&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel -r $username&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # DEBUG=1 diradm userdel $username&lt;br /&gt;
* Keeping the user on our [http://bismarck.iat.sfu.ca/mailman/admin/research/ Research Mailing List] is probably a good idea.&lt;br /&gt;
* If you delete a user, you MUST disallow diradm from ever using that UIDNumber again. To do so, go to each machine with diradm and edit the diradm.conf file so that UIDNUMBERMIN to equal the same number as the highest UIDNumber currently being used. (At least one higher than the user you deleted) This is important!&lt;br /&gt;
&lt;br /&gt;
== Changing a Users Password ==&lt;br /&gt;
This method does not require the old password.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # ldappass $username&lt;br /&gt;
&lt;br /&gt;
== Adding Users to a Group ==&lt;br /&gt;
Adding or removing from a group. Uses the same syntax as gpasswd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm gpasswd (-a|-d) $username $group&lt;br /&gt;
 # diradm gpasswd -a mdeepwel pond&lt;br /&gt;
&lt;br /&gt;
== Adding Groups ==&lt;br /&gt;
Adding groups takes the same syntax as groupadd(8).&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupadd $groupname&lt;br /&gt;
&lt;br /&gt;
To change the GID of any group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm groupmod -g GID $groupname&lt;br /&gt;
&lt;br /&gt;
== Adding Projects ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;: &lt;br /&gt;
 # diradm amadd -O $mapbase $key $src&lt;br /&gt;
 # diradm amadd -O home.projects meditation 209.87.56.240:/export/projects/0/m/meditation&lt;br /&gt;
* &#039;-O&#039; means the default mount options for automount.&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
** Make the $src directory. mkdir -p $src&lt;br /&gt;
** Set ownership. chgrp -R $group $src&lt;br /&gt;
** Set permissions. chmod 2771 $src&lt;br /&gt;
** If web content is being served: mkdir -p $src/htdocs ; chmod 2775 $src/htdocs&lt;br /&gt;
&lt;br /&gt;
== Adding CVS Repositories ==&lt;br /&gt;
Replace &#039;&#039;$foobar&#039;&#039; with the name of the repository.&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm amadd -O auto.cvs $foobar 209.87.56.240:/export/cvs/$foobar&lt;br /&gt;
* As root on &#039;&#039;&#039;yamato&#039;&#039;&#039;:&lt;br /&gt;
 # cvs -d /export/cvs/$foobar init&lt;br /&gt;
 # chmod -R 2770 /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a group, (assuming there&#039;s a previously created group called &#039;&#039;$foobar_group&#039;&#039;):&lt;br /&gt;
 # chgrp -R $foobar_group /export/cvs/$foobar&lt;br /&gt;
: If this repository is for a single user:&lt;br /&gt;
 # chown -R $user /export/cvs/$foobar&lt;br /&gt;
* Group name and cvs repository name don&#039;t have to match.&lt;br /&gt;
* To access CVS repo, use &#039;&#039;CVS_RSH=&amp;quot;ssh&amp;quot;&#039;&#039; with URL being &#039;&#039;:ext:$user@cvs.iat.sfu.ca:/var/cvsroot/$foobar&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Users must be in group cvs in addition to $foobar to access the repository!&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Adding SVN Repositories ==&lt;br /&gt;
&lt;br /&gt;
Note: $user represents a user&#039;s username, $group represents a new group that will need access to the repository, and $repository is the new name for the SVN repository.&lt;br /&gt;
&lt;br /&gt;
=== For a single user ===&lt;br /&gt;
&lt;br /&gt;
Add the user to the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $user /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
=== For multiple users ===&lt;br /&gt;
&lt;br /&gt;
Create a new group, and add all the users that require access to the newly created group as well as the svn group:&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;&lt;br /&gt;
 # diradm groupadd $group&lt;br /&gt;
 # diradm gpasswd -a $user $group&lt;br /&gt;
 # diradm gpasswd -a $user svn&lt;br /&gt;
&lt;br /&gt;
Create the repository and set the correct permissions:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin create /mnt/raid/svn/$repository --fs-type fsfs&lt;br /&gt;
 # chmod -R 2770 /mnt/raid/svn/$repository&lt;br /&gt;
 # chown -R $group /mnt/raid/svn/$repository&lt;br /&gt;
&lt;br /&gt;
* The repository URL is &#039;&#039;&#039;svn+ssh://$user@svn.iat.sfu.ca/$repository&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Dumping the contents of SVN Repositories to a file, and vice-versa ==&lt;br /&gt;
&lt;br /&gt;
Note: $repository represents the repository&#039;s name.&lt;br /&gt;
&lt;br /&gt;
To dump the contents to a file:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin dump /mnt/raid/svn/$repository &amp;gt; file.dump&lt;br /&gt;
&lt;br /&gt;
To load the contents from a file into a previously created repository:&lt;br /&gt;
* As root on &#039;&#039;&#039;hurricane&#039;&#039;&#039;&lt;br /&gt;
 # svnadmin load /mnt/raid/svn/$repository &amp;lt; file.dump&lt;br /&gt;
&lt;br /&gt;
== Adding Computers to the Domain ==&lt;br /&gt;
* As root on &#039;&#039;&#039;hood&#039;&#039;&#039;:&lt;br /&gt;
 # diradm smbhostadd sr-#####&lt;br /&gt;
* refer to [[Workstation_Naming_Convention]]&lt;br /&gt;
&lt;br /&gt;
== General User Management ==&lt;br /&gt;
* diradm offers almost all regular POSIX commands, sometimes with a few extra frills. The only commands NOT completely implemented are gpasswd and passwd.&lt;br /&gt;
* Welcoming new users; email template&lt;br /&gt;
** This is in the diradm.superadduser script, as it fills out the template.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
To: $fullname &amp;lt;$email&amp;gt;&lt;br /&gt;
Subject: Research account created - $newuser&lt;br /&gt;
&lt;br /&gt;
Hello $fullname&lt;br /&gt;
&lt;br /&gt;
Your research account has been created.&lt;br /&gt;
Username: $newuser&lt;br /&gt;
Password: $newpass&lt;br /&gt;
&lt;br /&gt;
Please visit http://research.iat.sfu.ca/network/changepassword.php to change&lt;br /&gt;
your password when you receive this email.&lt;br /&gt;
&lt;br /&gt;
For support with the research network, please email:&lt;br /&gt;
help@research.iat.sfu.ca&lt;br /&gt;
Please include a good description of the entire problem and a suitable subject&lt;br /&gt;
line.&lt;br /&gt;
&lt;br /&gt;
For more information about SIAT Research, visit our Research Wiki found at:&lt;br /&gt;
http://research.iat.sfu.ca/wiki/&lt;br /&gt;
&lt;br /&gt;
Please note that this username/password pair is only valid for the SFU Surrey&lt;br /&gt;
Research Network, and is NOT tied into the main SFU authentication systems.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sassafras K2 Keyserver Administration ==&lt;br /&gt;
=== Background ===&lt;br /&gt;
We use the [http://www.sassafras.com Sassafras] K2 Keyserver product for most license-compliance, primarily to extend the usefulness of a small number of licensed applications within the School of Interactive Arts &amp;amp; Technology (SIAT) Researcher community.  Most users are sporadic, and don&#039;t require full-time access to our specialized applications; rather, they need to accomplish a defined task which may be one component of their research or publication.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The Sassafras keyserver runs under Linux, on bismarck.iat.sfu.ca, with install-root under &#039;&#039;&#039;/usr/local/k2&#039;&#039;&#039;.&amp;lt;br&amp;gt;&lt;br /&gt;
In a process-listing, it shows up as:&lt;br /&gt;
 /usr/local/k2/ks -d -e /usr/local/k2/startup.txt&amp;lt;br&amp;gt;&lt;br /&gt;
It&#039;s started from an init-script under&lt;br /&gt;
 /etc/init.d/KeyServer&lt;br /&gt;
which, in turn, is launched upon startup by the Gentoo rc-update scripts.  No manual intervention is necessary (normally :-) ).&amp;lt;br&amp;gt;&lt;br /&gt;
We currently (2007) have 200 key-client licenses, which covers our current user-quantity, with some room for future growth.&amp;lt;br&amp;gt;&lt;br /&gt;
This keyserver serves licenses to Windows and Mac clients (only :-( ).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Administration ===&lt;br /&gt;
&lt;br /&gt;
The main administration tool is the K2Admin program, which is capable of running under Windows, or Mac OS-X (only :-( No Linux).&lt;br /&gt;
&lt;br /&gt;
Here is the [[Media:K2Admin.dmg|Local Mac Copy]]&amp;lt;br&amp;gt;&lt;br /&gt;
And, the [[Media:K2Admin.exe|Local Windows Copy]]&lt;br /&gt;
==== Viewing Key-served Applications ====&lt;br /&gt;
==== Adding Key-served Applications ====&lt;br /&gt;
==== Removing Key-served Applications ====&lt;br /&gt;
&lt;br /&gt;
== Flexlm License Server Administration ==&lt;/div&gt;</summary>
		<author><name>Hha13</name></author>
	</entry>
</feed>