Roaming Computing System (Windows Edition) 3.5
Create a User Account

Estimated time to complete: 30 minutes.

Contents

Syntax

Note that when a word in this guide is shown like <organisation> this means a variable, a placeholder, you're expected to enter here your particular word, not including the angle brackets.

Requirements

Twix, at least version 0.3.6, is used on the server. It should be in root's home directory. If you don't already have it then get it from thegoldenear.org/toolbox/unices/twix/ by logging into the server using PuTTY and following the instructions on the Twix web page.

Create Samba Account

Login to a workstation (as anyone) and run Start → Programs → PuTTY → PuTTY. Enter 'server' in the 'hostname' field and choose 'Connect'. If you've not run it before as this user choose 'Yes' to confirm the server is who you think it is. At the login prompt, enter 'root' and then when prompted the root Unix account password.

Run Twix: ./twix.sh → R

Other Optional Permissions

If you print through a print server on SERVER and want them to be a print administrator:
adduser <username> lpadmin

Create an Email Account

If they're to have a dedicated mailbox, it could be either in their own name (as per your organisation's naming convention), or the name of the role they're performing.

Go to the GRSoft Virtual Mail Manager at http://server/mailmanager/login.php (if logged in through the VPN you instead have to use http://10.0.0.10/mailmanager/login.php).

Login with your mail server administration account, either mail master account ('mailadmin@...') for the whole mail server, or individual domain account (postmaster@...) if you have one.

Manage virtual users → Select a virtual domain: → select domain → Add new virtual user to selected domain →

→ Save new virtual user

Add any forwardings if required (using Manage virtual aliases → Select a virtual domain → Select a virtual user → Add forwarding). A forwarding is a redirect, if you add one address to forward to it will redirect mail to that address. If you want mail to go to the original mailbox and also to be forwarded on to another, then add both addresses as forwardings seperately (I'm not sure if the ordering is important so add the original address first; 'To:' will be the person the original sender sent to; a forwarding and a virtual alias will be added simultaneously, each with the same id; if people ask for a forwarding for an additional mail address they instead most likely want a specific mailbox).

Add any aliases if required (using Manage virtual aliases → Select a virtual domain → Select a virtual user → Add virtual alias). Aliases are for if you want to create addresses that don't exist as a mailbox in their own right, that are only redirected to a different address. Add an alias using just the name part of the mail address, not including the domain part.

Test the mailbox and any forwardings and aliases by sending mail to them all from off-site.

Create Windows Profile and Configure

Logon to the workstation with the new account. Windows automatically creates a profile on the workstation, which it copies to the server when you logout. A lot of configuration of the new account will be automatically applied when you first login.

Manual Windows configuration:

Logoff now so these settings can take effect before continuing. Then logon again.

Software Configuration

Core RCS Software

(Creating Shortcuts; configuration of OpenOffice, IrfanView, Eraser, Sun Java Runtime Environment (JRE) and setting KompoZer as Default HTML Editor are made automaticaly through the logon script)

Firefox
Thunderbird

If they are to have access to any mailboxes, add each of them:

Add any additional mailboxes you want to use in the same way.

(If you mistakenly save a wrong password in Thunderbird you can remove the saved password using Tools → Options → Privacy → Passwords → Edit Saved Passwords)

Windows Media Player

Start → Programs → Windows Media Player → Custom Settings → Next

Picasa

Major Proprietary Applications (If Any)

For major proprietary applications (if any) that are likely to only be required on particular workstations see our separate guide to creating a user account (major proprietary applications).

Printing

If you print through a print server on SERVER - connect to any appropriate printers by navigating to the print server using Windows Explorer, i.e. \\server, right-click on the printer name and choose 'Connect'.

If you print direct to the printer (whether over USB, network or through hardware print server box) - the printer driver, as configured by the administrator for this workstation, will be already available and configured for this user.

If you have more than one printer configured (or pseudo printing device listed) then set whichever you want as the default printer: Start → Printers and Faxes → right-click on the specific printer → Set as default.

Do a test print.

Test that printing works.

Setting For Print Servers Outside Your Forest

If you're trying to 'Connect' to a print server not in your domain, to install the drivers to the workstation, as a Limited user, from a workstation using Windows XP SP1 or later, when you try to connect you get the message "a policy is in effect on your computer which prevents you from connecting to this print queue.". See www.pcreview.co.uk/forums/thread-554044.php and http://support.microsoft.com/kb/319939
This restriction is because "Win XP-SP1 introduced a Point and Print Restriction Policy (this restriction does not apply to "Administrator" or "Power User" groups of users). In Group Policy Object Editor, go to User Configuration → Administrative Templates → Control Panel → Printers. The policy is automatically set to Enabled and the Users can only Point and Print to machines in their Forest (en.wikipedia.org/wiki/Active_Directory#Forests.2C_trees.2C_and_domains). You probably need to change it to Disabled or Users can only Point and Print to these servers to make driver downloads from Samba possible."

Saving The Windows Profile (Optional)

Logout from the workstation. The newly configured user profile should be copied back to the server. Be careful, if the profile fails to copy to the server and you logon to a different workstation your changes will be lost. So keep a lookout for any messages such as "unable to save roaming profile", in which case you should log back in and out again.

Migration

If you're migrating from another system you may want to migrate these for the person: home directory / folder files; email; email Address books and distribution lists; browser bookmarks; browser saved passwords.