home *** CD-ROM | disk | FTP | other *** search
- -----------------------------------------------------------------------------
- 26th September 1995
- -----------------------------------------------------------------------------
- Support Group Application Note
- Number: 285
- Issue: 1.2
- Author: A McGregor
-
- -----------------------------------------------------------------------------
- Installing Acorn SchoolServer
- -----------------------------------------------------------------------------
- Notes:
- A standard routine and script to install Microsoft Windows NT Server on an IBM Power PC.
- This application note comes with two discs: a DOS formatted "Installation
- script" and a RISC OS formatted "OmniTest" disc containing the custom !Scrap
- required for use on an NT server.
-
- The instructions are a step-by-step guide to install NT software and a
- default directory structure to a standard configuration suitable for school
- use with Acorn workstations and Omniclient software. Server environment
- information, a DAT tape or two high-density blank floppy discs will be
- required.
- -----------------------------------------------------------------------------
- Applicable Hardware:
-
- Acorn SchoolServer
-
- Related Application Notes:
-
- 286 Bulk users & migration
- 287 User management
- -----------------------------------------------------------------------------
- Copyright (C) 1995 Acorn Computers Limited
-
- Every effort has been made to ensure that the information in this leaflet is
- true and correct at the time of printing. However, the products described in
- this leaflet are subject to continuous development and improvements and
- Acorn Computers Limited reserves the right to change its specifications at
- any time. Acorn Computers Limited cannot accept liability for any loss or
- damage arising from the use of any information or particulars in this
- leaflet. ACORN, ECONET and ARCHIMEDES are trademarks of Acorn Computers
- Limited.
- -----------------------------------------------------------------------------
- Support Group
- Acorn Computers Limited
- Acorn House
- Vision Park
- Histon
- Cambridge
- CB4 4AE
- -----------------------------------------------------------------------------
- Background
-
- For a variety of reasons it is desirable for the Acorn SchoolServer software
- to be installed in a standard way and for a standard directory structure to
- be installed by default. The installation procedure has been optimised for
- speed and the directory structure is suitable for a school environment,
- offering a base set of permissions for the use of Acorn specific resources
- on the fileserver and providing a standard template for user management.
- Standard installations are easier to support and any updates can be applied
- quickly from a script file usually without the need for a site visit.
-
- Administrator account
-
- It is always necessary to have a user account for emergency access to the
- whole server filesystem. Typically an installer will secretly create a
- "Backdoor" account for emergency use. With NT Server the Administrator
- account is the one account that cannot be deleted from the system (although
- it can be renamed) and is therefore a constant across all NT servers. Rather
- than a deleteable "backdoor", we strongly recommend the standard practice of
- only using the Administrator account for initial installation and for
- emergency fileserver administration thereafter. The Administrator password
- should be cryptic, about 10 characters long and a mixture of alpha and
- numeric characters but not car registrations or other guessable words. The
- written record of the password should be kept in a safe place with the
- original distribution media and the initial backup tape. We therefore
- recommend as standard practice the creation of an account called "Manager",
- which is a member of the "Administrators" group, and this is the account
- that the school's Network Manager uses to administer the fileserver on a
- day-to-day basis.
-
- Filesystem security and disc partitioning
-
- As a principle we recommend the use of NTFS rather than FAT for security.
- The IBM PowerPC requires the machine's proprietary boot files to be located
- on a hidden 5MB partition. We require all user data and programs to be on an
- NTFS partition but Windows NT requires a minimum set of "OS Loader" files to
- be on a FAT partition. The installation process will first create a 5MB
- machine boot partition (hidden), a 5MB OS Loader partition (Drive D) and the
- rest of the disc(s) will be formatted to NTFS (Drive C) and contain the
- Win32 operating system, Pagefile, Registry and the Apps, Resources and Users
- directory structure. Any additional discs should be formatted to NTFS and
- added to "Drive C" as a Volume Set; ie the additional discs appear to the
- user as a contiguous Drive C.
-
- Outline
-
- The installation proceeds in four phases, each punctuated by a reboot of the
- fileserver :
-
- Phase 1 - Boot computer from the ARC Boot disc.
- Do a Full Express Install from the Microsoft CD distribution media.
-
- Phase 2 - Create the operating system environment.
- You are required to enter the following details; have them
- ready before you start :
-
- Microsoft product serial number
- Server type, ie Primary/Backup Domain controller or Server
- Number of user licences purchased
- Computer Name
- Domain Name
- Administrator password
-
- Phase 3 - Customise the environment :
- Create a user called "Manager" and assign the user to the
- group "Administrators"
- Configure the NE2000 compatible ethernet card
- Configure the AS1000's DAT streamer
- Create the Acorn default directory structure
-
- Phase 4 - Establish connectivity, verify Manager access, establish !Scrap and
- make backups :
-
- Log on from an Acorn workstation using Omniclient
- Copy !Scrap to the C:\Resources directory.
- Reset the ScrapDirs security permissions to allow users to
- create and delete scrapfiles
- Create a backup tape of the completed installation or make
- recovery discs.
-
- Process
-
- Step-by-step instructions are numbered. Helpful comments describing the
- events that are taking place or background to the instructions are in
- brackets.
-
- Phase 1
-
- Phase 1 partitions and formats the 1st hard drive and copies on the boot
- files and the minimal operating system files required to boot.
-
- 1.1 Insert ARC Boot disc in floppy drive and power on.
-
- 1.2 The blue screen Main Boot Menu will appear; select the Installation
- and Setup menu option.
-
- 1.3 Choose "Simple Setup".
-
- 1.4 Select "Full Install", yes - Absolutely sure!.
-
- [A small 5MB ARC Boot Partition is created which is invisible to the
- user.]
-
- [Windows NT Boot files will now be placed in a small 5MB System FAT
- partition and the rest of the disc will be formatted to NTFS.]
-
- 1.5 On the next screen select "Two Drives"
-
- 1.6 On the next screen place the Microsoft NT Server CD in the drive and
- select "Set up ... from CD".
-
- 1.7 At the blue screen "Windows NT Server Setup", press ENTER to set up
- now.
-
- 1.8 Press ENTER for Express Setup.
-
- 1.9 There are no additional disc drive interface cards to set up at this
- stage, so press ENTER.
-
- [You now need to create an NTFS partition]
-
- 1.10 Move the highlight down to "Unpartitioned space" and press C to
- create.
-
- 1.11 Press ENTER to create a single large partition. [The maximum space
- available is highlighted]
-
- 1.12 Move the highlight bar down to "New (Unformatted)" and press ENTER
- to Install.
-
- 1.13 Move the highlight bar down to "Format ..... NTFS file system" and
- press ENTER to format the single large partition as NTFS. [This will
- take about 5 min/GB to format.]
-
- 1.14 Accept the default directory "\WINNT35" to install operating system
- files.
-
- [You have to reboot the computer and when this boots from the hard disc it
- recognises an incomplete installation. ]
-
- 1.15 Remove the ARC Boot floppy from the drive. Press ENTER to restart
- the computer
-
- Phase 2
-
- Phase 2 sets up the server's environment and configures the built-in
- hardware. The process requires you to enter the machine specific details and
- is critical to the installation. If some of the details entered are
- incorrect you may be required to re-do the installation from scratch!
-
- [The 1st screen requires the installer's name and company. This is not
- critical and is not used elsewhere.]
-
- 2.1 Enter the installer's name, TAB to the company field and enter the
- company name. Press ENTER to continue and ENTER again to confirm.
-
- [You need to enter the Product ID. Use the Microsoft serial number found on
- the Licence agreement document in the Warranties booklet. This is a 14 or 15
- character product ID (eg 32745-33-006nnnn)]
-
- 2.2 Enter the code, Click on "Continue" and again to confirm.
-
- [The first NT Server in a school is a Primary Domain Controller (PDC). You
- have to decide at this point whether the new installation is a "Domain
- Controller" or a data "Server".]
-
- 2.3 Unless the machine is going into an existing NT network, choose
- "Domain Controller (Primary or Backup)" and click on "Continue".
-
- [NT licencing is Per Server. You have purchased at least 25 concurrent
- licences by default as a 25 licence pack is shipped to the Customer by Acorn
- with every SchoolServer. Additional licence packs can be purchased in blocks
- of 25.]
-
- 2.4 Enter the number of licences purchased and click "Continue". Click
- on the box confirming that you agree to be bound by the terms of the
- licence and then click "OK".
-
- [The next screen is critical. Every machine on a Microsoft network has a
- unique Computer Name. We recommend using the computername "SchoolServer1" to
- cater for future multiple servers.]
-
- 2.5 Enter the Server's unique name; click "Continue" and again to
- confirm.
- Record the ComputerName on the Installation "Scope of Work" form for
- the records.
-
- 2.6 Select "English (United Kingdom)". Click "Continue" to set the
- localisation.
-
- [The next step is optional. If you do not wish to set up the printer now you
- can set it up in Print Manager later. You can click "Cancel" to skip to step
- 2.8]
-
- 2.7 Enter the printer's name and model. Remember the Printer Name is the
- name of the "Queue" and the Model is the name of the "printer
- driver" in normal parlance.
-
- [Setup now autodetects an Ethernet interface. The default on-board Ethernet
- interface is an "AMD PCNET PCI Ethernet Adapter v2.45". It has a UTP
- connector.]
-
- 2.8 From the pulldown menu under "Full Duplex" select "UTP". Then click
- in the "TP" box to select Twisted Pair, and "Continue".
-
- 2.9 Click "Continue" to accept the defaults of "NWLINK" and "NetBEUI"
- network protocols.
-
- [The remaining operating system files are now copied from the CD. This takes
- 10 minutes or so.]
-
- 2.10 Click OK to select "Auto Frame Type Detection" for the inbuilt
- ethernet interface.
-
- [The next screen will be different if the computer will not be a Domain
- Controller but just a data Server. The Domain Name must be unique on any
- Microsoft network. If the machine is going in as a Domain Controller then
- you have to choose at this point whether it is a Primary or Backup Domain
- Controller. If it will be a Backup Controller then the ethernet cable needs
- to be connected now to allow the installation process to authenticate the
- new controller in the Domain. If the machine is a Primary Domain Controller
- then click on the "Primary Domain Controller" button and enter the Domain
- Name in the box alongside; we recommend the use of an abbreviated school
- name as the Domain Name, such as "StBedes", or "DulwichCS".]
-
- 2.11 Select the required type of Domain controller. Record the Domain
- Name on the Installation "Scope of Work" form for the records.
-
- [The Administrator account is to be used for emergency purposes only. You
- will later create a Manager account with Administrator privileges for the
- general administration of the SchoolServer. The Administrator password needs
- to be set; we recommend you choose a 10 character combination of alpha and
- numeric eg DX4pl57HwT.]
-
- 2.12 Enter the Administrator's password. Record the password on the
- Installation "Scope of Work" form for the records.
-
- 2.13 Click "Continue" to select the default list of applications, eg the
- default DOS editor.
-
- 2.14 Set the time and date if necessary (note the date is still in
- American format, ie mm/dd/yy). Click the box to "Automatically
- adjust for Daylight Saving". The Time Zone is GMT. Click "OK" when
- set.
-
- 2.15 The display adaptor is detected. Click "OK", click "Test", click
- "OK" and the screentest is completed. Assuming this has appeared
- correctly then click "OK" and "OK" again to save the settings. Click
- "OK" on the Display Settings screen.
-
- 2.16 The configuration is saved. Do NOT make an Emergency Repair Disk
- yet.
-
- 2.17 Remove the boot disc and click "Restart" to reboot the installed
- SchoolServer.
-
- Phase 3
-
- The operating system is now fully installed. Phase 3 creates the Manager
- account and configures the optional hardware. The Acorn default directory
- structure is created from a batch file on the floppy disc supplied.
-
- [At the startup screen you can optionally press ENTER to accelerate the boot
- process.]
-
- 3.1 Ctrl-Alt-Del to log on. Log on as Administrator; you have the
- password.
-
- [You will now create a user called "Manager" and assign the user to the
- Administrators group to give the Manager full administrative privileges. The
- Network Manager will use the "Manager" account for day-to-day administration
- of the server.]
-
- 3.2 From Administrative Tools select User Manager for Domains. From the
- "User" dropdown menu select "New User" and enter "Manager" as the
- Username. The name of the Network Manager and the description boxes
- are optional fields. Leave the Password fields blank unless the
- Network Manager specifies a password. Remove the "X" from the "Must
- change password" box by clicking on it. Click on the "Groups"
- button at the bottom of the window. Highlight the group
- "Administrators" and click "Add" to make the Manager a member of the
- Administrators group. Click "OK" to confirm and "Add" to create the
- account in the security system. Close the New User and User Manager
- windows.
-
- [The system is shipped with an NE2000 compatible ethernet card as standard.
- You need to configure Windows NT to use it. The card should be configured to
- use IRQ 11, Port 300 and the BNC connector in the factory. If you require to
- use the RJ45 connector then you will need to reconfigure the card at the
- next machine reboot using the SMS disc.]
-
- 3.3 From the "Main" window open the Control Panel and select "Network".
- Select "Add Adaptor" and open the list of "Network Adaptor Cards".
- Accept "e:\ppc\" as the location of the installation files.
- Scroll down to "Novell NE2000 Compatible Adapter" and click "OK".
- Change "IRQ Level" to 11 and "I/O Port Address" to 0x300 and click "OK".
- The Bus location is "Type ISA" and "Number 0"; click OK.
- Click "Continue" and the driver file will be copied from the CD ROM in the
- drive.
- Click "OK" in the Network Settings window to write the configuration to
- the Registry.
- Select the second adaptor from Adapter options and set "Auto Frame Type"
- for the NE2000 card.
- Do NOT reboot. [You will be requested to reboot the computer now to
- activate the NE2000 NIC but ignore this for now.] Click "don't restart now".
-
- [An AS1000 system will require the tape streamer to be set up. Skip this
- step if you do not have a DAT streamer installed.]
-
- 3.4 From the Main window open "Windows NT Setup".
- From the "Options" dropdown menu select "Add/Remove Tape Device".
- Select "Add" and choose "4mm DAT Drive" and click "OK".
- The path to the CD drive is displayed. Click "Continue".
- Close the window but do NOT reboot the machine at this stage as the system
- may suggest.
-
- [The next step is to create the Acorn default directory structure]
-
-
-
- 3.5 Place the "Installation Script" floppy in Drive A.
- Open the MS-DOS Command Prompt window (in Main).
- Run the batch file "A:\FILESYST.BAT".
- Some of the Acorn specific Shares will not be seen by DOS based systems and
- the script may remind you of this. Just accept with "Y" at each prompt.
-
- 3.6 Close all open windows and remove the floppy disc from the drive.
- Reboot the machine (Ctrl-Alt-Del). Select "Shutdown", "Shutdown + restart" and
- click "OK".
- [The NE2000 card and the DAT streamer will now be recognised.]
-
- Phase 4
-
- Phase 4 copies !Scrap (and optionally any other Acorn specific resources) to
- the fileserver. These must reside within the C:\Resources directory. We have
- provided a tailored version of Omniclient called !Identify which detects the
- network card in the Acorn workststion and starts up Omniclient configured
- for LanManager connectivity only.
-
- 4.1 From a suitable connected Acorn workstation run (left-DoubleClick)
- the "!Identify" application from the "OmniTest" floppy disc.
-
- Menu (middle button) over the Omniclient icon on the Icon Bar.
- Select "Mounts" and then "Protocols" and select (left button) "Lan Manager".
- Enter the following into the dialog boxes :
- Name School
- Server name SchoolServer1 (or the computer name you entered in step
- 2.5 above)
- Directory path Resources
- User name Manager
- Password (leave blank unless the Manager account has a password)
- A window should open on the screen entitled "LanMan::NTServer.$"
-
- 4.2 Drag the !Scrap folder on the floppy disc into the window.
- Optionally drag any other required resources to the LanMan window, eg
- !System, !Fonts, !Printers.
-
- 4.3 Dismount the NTServer (middle button) on the NTServer icon on the icon bar.
-
- [You now need to reset the ScrapDirs security permissions to allow users to
- create and delete scrapfiles but not to see them.]
-
- 4.4 Log on at the SchoolServer (Ctrl-Alt-Del) using the Manager account.
- From the "Main" window open the File Manager and click on Drive C.
- DoubleClick Resources then !Scrap then select "ScrapDir.~s".
-
- [With the folder "Scrapdir.~s" highlighted you must now reset its
- Security Permissions.]
-
- From the "Security" dropdown menu select "Permissions".
- Highlight the group Everyone.
- ["Type of access" needs to be set to "Add (WX)(Not specified)"].
- Do this from the Special directory access and Special file access options.
- Click "OK" to reset the permissions on the directory.
-
- [On an AS1000 you should finally create a backup tape of the completed
- installation including the Registry to keep safe with the Microsoft
- distribution CD ROM and Administrator password. This can be used to restore
- the default installation state on a bootable NT system in the future. If
- there is no tapestreamer available you should skip to step 4.6 and create an
- "Emergency Repair Disk".]
-
- 4.5 Open the "Backup" application from the the Administrative Tools window.
- Check the box against Drive C and click the backup button.
- Ensure you check the box to backup the registry.
- Click "OK" to commence backup.
- When finished, exit the Backup application, remove the tape.
- Label the tape "Initial installation".
-
- [IF you have backed up the fileserver to tape, THEN omit the following two
- steps and go to step 4.8 - you have finished the installation; ELSE you must
- have a blank high-density unformatted diskette ready to create an Emergency
- Repair Disk and a blank high-density DOS-formatted (1.44MB) diskette to
- backup the Registry, providing you have a copy of the Resource Kit
- containing REGBACK.]
-
- 4.6 Open the MS-DOS "Command Prompt" from the Main window.
- Put an unformatted high-density diskette in the floppy drive.
- Run the DOS executable file RDISK.EXE from the C:> prompt.
- Click "Create Repair Disk"
- Click "OK" to format if it asks. [The diskette is formatted and the
- configuration files copied to it.]
- Click "Exit" when finished.
- Close the MS-DOS window and remove the diskette from the drive.
- Label the diskette "Initial installation - Emergency Repair Disk"
-
- 4.7 Open the MS-DOS "Command Prompt" from the Main window.
- Put a 1.44MB DOS-formatted high-density diskette in the floppy drive.
- At the C:> prompt type "REGBACK A:\" [The Registry files are copied to the floppy.]
- Close the MS-DOS window and remove the diskette from the drive.
- Label the diskette "Initial installation - Registry Backup"
-
- 4.8 Shut down the fileserver (Ctrl-Alt-Del) and ensure the Network
- Manager has successfully started up, logged-on, safely shut down and knows
- how to backup the fileserver.
-
- 4.9 Complete the Installation "Scope of Work" form and the "Owner
- Registration Card" (inside the Welcome Guide). Obtain a signature on the
- form from the Network Manager confirming his acceptance of the installation
- to specification.
-
- 4.10 Photocopy the SIGNED Installation "Scope of Work" form twice; one
- copy is for the Network Manager to retain and one copy must be sent to IBM
- to trigger the commencement of the on-site service contract. The original
- must be returned to Acorn together with the completed Owner Registration
- Card.
-
- 4.11 Ensure the Network Manager has for safe keeping the :
- Microsoft distribution CD and warranty card,
- Arc Boot disc,
- IBM SMS disc,
- Administrator password,
- Installation backup tape (or Emergency Repair Disk + Registry Backup),
- Signed copy of the Installation "Scope of Work" form,
- Retained portion of the completed Owner Registration Card.
-
- 4.12 Tidy the packaging and go home.
-
-
-
-
- Appendix 1 - FILESYST.BAT - Installation Script
-
- This is a DOS batch file
-
- rem this assumes 1 big NTFS partition
- rem else 200MB for FAT on C: and substitute d: for c: below
- rem create user Manager in Administrators before running
- cacls c:\ /G administrators:F "creator owner":F
- md c:\Resources
- cacls c:\Resources /T /E /G everyone:R
- rem the following are listed to describe where the resources go
- rem md c:\Windows31
- rem md c:\Windows95
- rem cacls c:\Windows31 /T /E /G everyone:RW
- rem cacls c:\Windows95 /T /E /G everyone:RW
- rem md c:\DOS
- rem cacls c:\DOS /T /E /G everyone:R
- md c:\Apps
- cacls c:\Apps /T /E /G everyone:R
- md c:\Apps\ClipArt
- md c:\Apps\Programs
- md c:\Apps\Utils
- md c:\Users
- md c:\Users\Manager
- md c:\Users\Headmstr
- md c:\Users\Office
- md c:\Users\Yearhead
- md c:\Users\Subjhead
- md c:\Users\Staff
- md c:\Users\Students
- md c:\Users\Students\95
- md c:\Users\Students\94
- md c:\Users\Students\93
- md c:\Users\Students\92
- md c:\Users\Students\91
- rem now create the student classes beneath each year eg \Users\Students\95\xxx
- cacls c:\Users\Manager /T /E /G manager:F
- net share Apps=c:\Apps
- net share Resources=c:\Resources
- rem now share the subdirectories to the created groups
- rem eg net share Yearheads=c:\Users\Yearhead
- rem eg net share 95xxx=c:\Users\Students\95\xxx
- rem with Omni copy !Scrap to \Resources\
- rem & reset permissions of ScrapDirs to (RWX)(Not specifed)
- rem copy !System, !Fonts, !Printers, !ARMovie etc to c:\Resources\
- rem and anything else that may be made available during a Boot sequence
-
-
- Appendix 2 - CACLS.EXE
-
- CACLS filename [/T] [/E] [/C] [/G user:perm] [/R user [...]]
-
- [/P user:perm [...]] [/D user [...]]
-
- filename Displays ACLs.
-
- /T Changes ACLs of specified files in
-
- the current directory and all subdirectories.
-
- /E Edit ACL instead of replacing it.
-
- /C Continue on access denied errors.
-
- /G user:perm Grant specified user access rights.
-
- Perm can be: R Read
-
- C Change (write)
-
- F Full control
-
- /R user Revoke specified user's access rights.
-
- /P user:perm Replace specified user's access rights.
-
- Perm can be: N None
-
- R Read
-
- C Change (write)
-
- F Full control
-
- /D user Deny specified user access.
-
- Wildcards can be used to specify more that one file in a command.
-
- You can specify more than one user in a command.
-
-
- Appendix 3 - Installation "Scope of Work" form
-
- This form must be completed at every SchoolServer installation. It confirms
- Acorn's contract with the Customer, establishes the scope of the
- installation process and receipt of the acceptance signature triggers the
- on-site service facility for the Customer.
-
- The original signed copy is to be returned to Acorn :
-
- Alastair McGregor
- Acorn Computers Ltd
- Vision Park
- Histon
- Cambridge CB4 4AE
- Tel : 01223 254491
-
- You should include the completed tear-off part of the Owner
- Registration Card with the form.
-
- One photocopy is for retention by the Customer.
-
- One photocopy is for IBM and triggers provision of the on-site service :
- Acorn Hotline
- IBM Service Plus
-
- Sale
- M......
- Tel : 0161
- Fax : 0161
-
-