What are the issues corrected in Directory and Resource Administrator 8.1 SP1? (NETIQKB70989)

  • 7770989
  • 18-Mar-2008
  • 24-Sep-2008

Environment

DRA 8.1 SP1 KB Placeholder Number 3

Situation

What are the issues corrected in Directory and Resource Administrator 8.1 SP1?
Why should I install/upgrade to Directory and Resource Administrator 8.1 SP1?

Resolution

Directory and Resource Administrator (DRA) and Exchange Administrator (ExA) provide highly secure and automated administration of Microsoft Windows 2000 Server, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Exchange 2000 Server, Microsoft Exchange Server 2003, and Microsoft Exchange Server 2007. Through improved scalability, advanced delegation, and powerful policy-based management capabilities, DRA and ExA increase Active Directory security, dramatically reduce administrative efforts and costs while increasing efficiency, and protect the integrity of data in your Microsoft Windows 2000 Server Active Directory, Microsoft Windows Server 2003 Active Directory, and Microsoft Exchange directory.

DRA and ExA 8.1 Service Pack 1 provides improvements and corrects issues found in DRA and ExA 8.1. NetIQ Corporation has made many of these improvements in direct response to suggestions from customers. Thank you for your time and valuable input.

This document outlines why you should install this service pack, provides additions to the documentation, and identifies any known issues. We assume you are familiar with previous versions of these products. For more information about installing these products, see the Installation Guide.

Issues Addressed in This Service Pack

The following section outlines some issues that this service pack corrects:

The DRA Server Stops Running When Memory Utilization Crosses a Certain Threshold Due To Memory Leaks

This service pack resolves an issue that caused the DRA server to stop running when memory utilization crossed a certain threshold due to memory leaks. DRA now optimizes memory utilization and no longer exceeds the available memory.

DRA Does Not Successfully Restore Deleted Objects from the DRA Recycle Bin If the Domain Controller That Holds the Relative ID Master Role Was Unavailable During Object Deletion

This service pack resolves an issue where DRA was not successfully restoring deleted objects from the DRA Recycle Bin if the domain controller that holds the Relative ID (RID) Master role was unavailable during object deletion. DRA now prevents you from deleting objects to the DRA Recycle Bin if the domain controller that holds the RID Master role is unavailable.

DRA Disables Object Properties and Exchange Management Tasks in the Advanced Search Results Pane If You Select Multiple Objects

This service pack resolves an issue where DRA was disabling object properties and Exchange management tasks if you selected multiple objects in the advanced search results pane. DRA now does not disable object properties and Exchange management tasks if you select multiple objects in the advanced search results pane.

DRA Not Automatically Displaying Alias of Cloned User Account with Mailbox

This service pack resolves an issue where DRA was not automatically displaying the alias while cloning a user account with a mailbox. DRA now automatically displays the alias on the Exchange General tab while cloning a user account with a mailbox.

Fields on User Interface Extension Pages Appear Mandatory

This service pack resolves an issue where DRA displayed fields on user interface extension pages as mandatory. If you left any field on the user interface extension pages blank, DRA displayed a warning message, but allowed you to create users. DRA now does not display the warning message if you leave any field on the user interface extension page blank.

Permanently Deleting Certain Objects from the DRA Recycle Bin

This service pack partly resolves an issue where the DRA Recycle Bin did not allow you to permanently delete objects that had other objects associated with them. For example, previously DRA did not permanently delete computer objects associated with serviceConnectionPoint objects. DRA now allows you to permanently delete computer objects that have other objects associated with them.

Note: DRA does not allow you to permanently delete users, contacts, or groups that have other objects associated with them.

Assistant Admins with Manage Clone Exceptions Power Cannot View Clone Exceptions

This service pack resolves an issue where DRA did not allow Assistant Admins (AAs) with the Manage Clone Exceptions power to view clone exceptions. DRA now ensures AAs with the Manage Clone Exceptions power can view clone exceptions.

Assistant Admins with Clone User and Modify All Properties Power or Clone User and Modify Limited Properties Power Get An Error Message When Cloning Users

This service pack resolves an issue in DRA where AAs with the Clone User and Modify All Properties power or Clone User and Modify Limited Properties power got an error message when cloning users. DRA now ensures AAs with the Clone User and Modify All Properties power or Clone User and Modify Limited Properties power can clone users without getting any error message even when they do not have the View Clone Exceptions power.

DRA Displays Constraint Violation Error Message While Creating Computers

This service pack resolves an issue where DRA displayed a constraint violation error message when you tried to create computers. DRA now does not display the error message when you create computers.

Advanced Search Details Pane Resizing on Loading Queries

This service pack resolves an issue where DRA was resizing the advanced search details pane every time you loaded an advanced query. DRA now does not resize the advanced search details pane when you load a query.

Advanced Search Results Pane Not Displaying Email Addresses of Objects

This service pack resolves an issue where DRA was not displaying the email addresses of objects in the advanced search results pane whenever you executed an advanced query. If you executed an advanced query where Email Address was one of the selected columns, DRA did not display the email addresses of objects in the advanced search results pane. DRA now displays email addresses of objects that are listed in the advanced search results pane.

DRA Not Displaying Correct License Information When You Install Different License Types

This service pack resolves an issue where DRA was not displaying the correct license information when you installed different types of licenses. For example, if you initially installed trial licenses and then upgraded the licenses to replacement licenses before finally upgrading to purchased licenses, if you checked the license information on the License tab of the DRA Properties window, the license information might be incorrect. DRA now correctly displays the license information.

DRA Sometimes Displays A Warning When You Clone Users

This service pack resolves an issue where DRA was sometimes displaying a warning when you cloned users using the Delegation and Configuration console or Account and Resource Management console. Although DRA correctly cloned users, DRA displayed the warning, "The user account you are creating cannot be granted the same group memberships as the cloned user account. You do not have the appropriate power to grant the new user account all the same group memberships." DRA now does not display this warning.

DRA Clones Groups under Different Path When Cloning Groups Using Web Console

This service pack resolves an issue where DRA did not clone groups in the same path where the source groups were available when you cloned groups using the Web Console. DRA cloned the groups in the User container for that domain. DRA now correctly clones groups in the same path as the source groups.

DRA Not Removing Service Connection Point Entries of the Managed Domain or Member Computers from Active Directory When You Remove the Managed Domain or Member Computers

This service pack resolves an issue where DRA did not remove Service Connection Point (SCP) entries of the managed domain or member computers from Active Directory when you removed the managed domain or member computers from the list of managed objects. DRA now removes the SCP entries of the managed domain or member computers from Active Directory when you remove the managed domain or member computers from the list of managed objects.

DRA Allowing AAs to View the Virtual Attributes Node By Default in the Delegation and Configuration Console

This service pack resolves an issue where DRA was allowing AAs to view the Virtual Attributes node by default in the Delegation and Configuration console. DRA now only allows AAs with the necessary permissions to view the Virtual Attributes node in the Delegation and Configuration console.

DRA Does Not Validate Required Custom Policy Fields When Cloning Users

This service pack resolves an issue where DRA was not validating required custom policy fields while cloning users. For user interface extension pages you created that included a required custom policy field, if you updated the user interface extension page while creating a new user and then cloned the user, DRA was not able to validate the required custom policy field for the cloned user. DRA now correctly validates required custom policy fields when cloning users.

The Display Name Values for Groups Are Not Available in the Search Results Pane of the Account and Resource Management Console and the Delegation and Configuration Console

This service pack resolves an issue where DRA was not displaying the Display Name values for groups in the search results pane of the Account and Resource Management console and the Delegation and Configuration console. DRA now correctly displays the values for the Display Name column for groups in the search results pane.

DRA Unable to Manage Certain Existing Mailboxes

This service pack resolves an issue where DRA was unable to manage certain existing Microsoft Exchange 2000 Server mailboxes because DRA identified these mailboxes, where the homeMDB property value was set as Private Information Store, as Microsoft Exchange 5.5 mailboxes. DRA now correctly identifies Microsoft Exchange 2000 Server mailboxes and allows you to manage these mailboxes.

Change in the Names, Descriptions, and Categories of Microsoft Exchange 2000 Server and Microsoft Exchange Server 2003 Powers and Roles

This service pack changes the names, descriptions, and categories of Microsoft Exchange 2000 Server and Microsoft Exchange Server 2003 powers and roles to indicate support for Microsoft Exchange Server 2007. For example, the Clone Exchange 2000/2003 Mailbox and Modify All Properties power is now known as Clone Exchange Mailbox and Modify All Properties.

Incorrect Field Label on Email Address Tab of Establish Email Address Wizard for Groups

This service pack resolves an issue where DRA was incorrectly displaying the Email address label on the Email address tab of the Establish Email Address wizard for groups. DRA now does not display the Email address label on the Email address tab of the Establish Email Address wizard for groups.

DRA Not Updating Alias Field When You Move Back Through the Create User Wizard after Enabling Mailbox

This service pack resolves an issue where DRA was not updating the Alias field when you moved back through the Create User wizard and made changes to the user name after enabling the mailbox for the user. DRA now correctly reflects the changes to the user name in the Alias field when you move back through the Create User wizard after enabling the mailbox.

DRA Unable to Execute Advanced Searches When Querying Untrusted Domains

This service pack resolves an issue where DRA was unable to execute advanced searches when you used an access account to query an untrusted domain in a different forest. DRA now allows you to execute advanced searches when you use an access account to query an untrusted domain in a different forest.

DRA Not Setting Microsoft Exchange Mailbox Permissions for Well-Known Security Principals

This service pack resolves an issue where DRA did not allow you to set permissions for well-known security principals on the Mailbox security tab and Mailbox rights tab of the User Properties window. DRA now allows you to find well-known security principals on the Mailbox security tab and Mailbox rights tab of the User Properties window and set permissions for these security principals.

NetIQ Administration Service May Stop Running When You Move Mailboxes between Different Microsoft Exchange Servers

This service pack resolves an issue where the NetIQ Administration service sometimes stopped running when you moved mailboxes between different Microsoft Exchange servers. DRA now ensures that the NetIQ Administration service does not stop running when you move mailboxes between different Microsoft Exchange servers.

Web Console Does Not Accurately Identify Incorrect Object Names When Verifying Names of Objects Added to Groups

This service pack resolves an issue in the Web Console where DRA did not accurately identify incorrect object names from a list of objects added to a group. If you added a list of objects to a group using the Web Console, if you added an incorrect object name in the list and then tried to verify the object names in the list, DRA did not identify incorrect object names. DRA now accurately identifies incorrect object names when you verify object names from a list of objects that you have added to a group using the Web Console.

Assistant Admins Unable to View and Select Containers while Modifying Advanced Queries

This service pack resolves an issue where DRA did not allow AAs with the necessary powers to view and select containers while modifying advanced queries. DRA now allows AAs to view containers in all managed domains, whether or not they are members of ActiveViews.

DRA Not Restoring Group Members to a Group Restored from the DRA Recycle Bin

This service pack resolves an issue where DRA did not restore the group membership of a deleted group that you restored from the DRA Recycle Bin after you performed a full accounts cache refresh. DRA now restores the group membership when you restore a deleted group from the DRA Recycle Bin.

Additional Information

Formerly known as NETIQKB70989

Issues corrected cont.:

DRA Performs a Scheduled Backup of the Registry and Provides a Utility to Restore the Registry Settings

This service pack helps resolve a possible issue with unexpected changes to the registry settings under HKEY_LOCAL_MACHINE\SOFTWARE\Mission Critical Software\OnePoint\ when you install or uninstall Microsoft Operations Manager (MOM) components or System Center Operations Manager (SCOM) components. DRA now performs a scheduled backup of the registry and stores the registry settings in a file under Program Files\NetIQ\DRA\BackupRegFiles. DRA maintains two backup files. If there is a change in the registry settings, you can use the DRARegRestore utility under the installation folder to restore the backed-up registry settings. If you want to change the backup schedule, you need to change the registry settings in the BackupRegistry.Freq key under HKEY_LOCAL_MACHINE\SOFTWARE\Mission Critical Software\OnePoint\Administration\Modules\ServerConfiguration\. In the BackupRegistry.Freq key, the default value is Weekly 6 00:00, where 6 indicates Saturday. You can change the day by using any number between and including 0 and 6, where 0 indicates Sunday. You need to use the 24-hour time format when specifying the time.

Installing This Service Pack

To benefit from the new features and fixes provided in this service pack, install it on each Administration server computer and on each computer where you installed an Account and Resource Management console or Delegation and Configuration console.

You should have DRA and ExA 8.1 already installed on your computer. To upgrade to DRA and ExA version 8.1, install the new version over your existing version. Do not uninstall your existing version.

To install this service pack:

  1. Download the NetIQ Directory and Resource Administrator and Exchange Administrator 8.1 Service Pack 1 installation program.
  2. Double-click the DRA810_SP1.msi file.
  3. Follow the on-screen instructions to complete the installation.

Note:

  • To enable support for Microsoft Exchange Server 2007, install Microsoft Exchange Server 2007 Service Pack 1 on computers running Microsoft Exchange Server 2007 and on computers running DRA and ExA 8.1.
  • DRA performs a full account cache refresh after you install DRA and ExA 8.1 Service Pack 1.
  • You cannot install DRA and ExA 8.1 on a computer running Microsoft Windows Server 2008, but you can install DRA and ExA 8.1 on a computer running Microsoft Windows Server 2003 that is part of a Microsoft Windows Server 2008 domain.
  • You cannot install the DRA agent on a read-only domain controller or a server core installation of Microsoft Windows Server 2008.
  • Note: For more information on the new features and functions in DRA 8.1 SP1 see: NETIQKB70990.