ja.po revision 9a839b29816c8906d4a6b074cf76df790cac9209
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# SOME DESCRIPTIVE TITLE
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# Copyright (C) YEAR Red Hat
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# This file is distributed under the same license as the sssd-docs package.
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek# Tadashi Jokagi <elf@poyo.jp>, 2012
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# Tomoyuki KATO <tomo@dream.daynight.jp>, 2012-2013
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# carrotsoft <www.carrotsoft@gmail.com>, 2012
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Project-Id-Version: sssd-docs 1.15.3\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Report-Msgid-Bugs-To: sssd-devel@redhat.com\n"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"POT-Creation-Date: 2017-10-20 16:15+0200\n"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"PO-Revision-Date: 2014-12-14 11:59-0500\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Last-Translator: Copied by Zanata <copied-by-zanata@zanata.org>\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Language-Team: Japanese (http://www.transifex.com/projects/p/sssd/language/"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Language: ja\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"MIME-Version: 1.0\n"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Content-Type: text/plain; charset=UTF-8\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Content-Transfer-Encoding: 8bit\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Plural-Forms: nplurals=1; plural=0;\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"X-Generator: Zanata 3.9.6\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_groupmod.8.xml:5 sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sss-certmap.5.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:5 sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_obfuscate.8.xml:5 sss_override.8.xml:5 sss_useradd.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-krb5.5.xml:5 sss_groupadd.8.xml:5 sss_userdel.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupdel.8.xml:5 sss_groupshow.8.xml:5 sss_usermod.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_cache.8.xml:5 sss_debuglevel.8.xml:5 sss_seed.8.xml:5 sssd-ifp.5.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_rpcidmapd.5.xml:5 sss_ssh_authorizedkeys.1.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:5 idmap_sss.8.xml:5 sssctl.8.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-files.5.xml:5 sssd-secrets.5.xml:5 sssd-session-recording.5.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SSSD Manual pages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SSSD マニュアル ページ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:10 sss_groupmod.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_groupmod"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "sss_groupmod"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refmeta><manvolnum>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupmod.8.xml:11 pam_sss.8.xml:12 sssd_krb5_locator_plugin.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:11 sss_obfuscate.8.xml:11 sss_override.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:11 sss_groupadd.8.xml:11 sss_userdel.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:11 sss_groupshow.8.xml:11 sss_usermod.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_cache.8.xml:11 sss_debuglevel.8.xml:11 sss_seed.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: idmap_sss.8.xml:11 sssctl.8.xml:11 sssd-kcm.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "modify a group"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "グループを変更します。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupmod.8.xml:30 sssd-ldap.5.xml:21 pam_sss.8.xml:57
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd_krb5_locator_plugin.8.xml:20 sssd-simple.5.xml:22 sss-certmap.5.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:21 sssd-ad.5.xml:21 sssd-sudo.5.xml:21 sssd.8.xml:29
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:30 sss_override.8.xml:30 sss_useradd.8.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:21 sss_groupadd.8.xml:30 sss_userdel.8.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:30 sss_groupshow.8.xml:30 sss_usermod.8.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_cache.8.xml:29 sss_debuglevel.8.xml:30 sss_seed.8.xml:31
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ifp.5.xml:21 sss_ssh_authorizedkeys.1.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:31 idmap_sss.8.xml:20 sssctl.8.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-files.5.xml:21 sssd-secrets.5.xml:21 sssd-session-recording.5.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-kcm.8.xml:21 sssd-systemtap.5.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "DESCRIPTION"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupmod</command> modifies the group to reflect the changes "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"that are specified on the command line."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>sss_groupmod</command> はコマンドラインにおいて指定された変更を反映"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"するようグループを変更します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_groupmod.8.xml:39 pam_sss.8.xml:64 sssd.8.xml:42 sss_obfuscate.8.xml:58
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:39 sss_groupadd.8.xml:39 sss_userdel.8.xml:39
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:39 sss_groupshow.8.xml:39 sss_usermod.8.xml:39
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_cache.8.xml:39 sss_seed.8.xml:42 sss_ssh_authorizedkeys.1.xml:66
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "OPTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_groupmod.8.xml:43 sss_usermod.8.xml:77
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Append this group to groups specified by the <replaceable>GROUPS</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"a comma separated list of group names."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"このグループを <replaceable>GROUPS</replaceable> パラメーターにより指定された"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"グループに追加します。 <replaceable>GROUPS</replaceable> パラメーターはグルー"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"プ名のカンマ区切り一覧です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_groupmod.8.xml:57 sss_usermod.8.xml:91
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Remove this group from groups specified by the <replaceable>GROUPS</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable> parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"このグループを <replaceable>GROUPS</replaceable> パラメーターにより指定された"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.conf.5.xml:11 sssd-ldap.5.xml:11 sssd-simple.5.xml:11
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss-certmap.5.xml:11 sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:11 sssd-ifp.5.xml:11 sss_rpcidmapd.5.xml:27
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-files.5.xml:11 sssd-secrets.5.xml:11 sssd-session-recording.5.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refmeta><refmiscinfo>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:12 sssd-ldap.5.xml:12 sssd-simple.5.xml:12
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss-certmap.5.xml:12 sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:12 sssd-ifp.5.xml:12 sss_rpcidmapd.5.xml:28
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-files.5.xml:12 sssd-secrets.5.xml:12 sssd-session-recording.5.xml:12
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-kcm.8.xml:12 sssd-systemtap.5.xml:12
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "File Formats and Conventions"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ファイル形式および変換"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "the configuration file for SSSD"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "SSSD の設定ファイル"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FILE FORMAT"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ファイルフォーマット"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>[section]</replaceable>\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The file has an ini-style syntax and consists of sections and parameters. A "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"section begins with the name of the section in square brackets and continues "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"until the next section begins. An example of section with single and multi-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ファイルは ini 形式の構文を持ち、セクションとパラメーターから構成されます。セ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"クションは角括弧にあるセクション名から始まり、次のセクションが始まるまで続き"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ます。 1 つセクションと複数の値を持つパラメーターの例: <placeholder type="
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The data types used are string (no quotes needed), integer and bool (with "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"values of <quote>TRUE/FALSE</quote>)."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"使用されるデータ形式は、文字列(引用符は不要)、整数および論理値"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(<quote>TRUE/FALSE</quote> の値)です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A line comment starts with a hash sign (<quote>#</quote>) or a semicolon "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(<quote>;</quote>). Inline comments are not supported."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"All sections can have an optional <replaceable>description</replaceable> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameter. Its function is only as a label for the section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"すべてのセクションはオプションの <replaceable>description</replaceable> パラ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"メーターを持てます。その機能はセクションのラベルとしてのみです。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<filename>sssd.conf</filename> must be a regular file, owned by root and "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"only root may read from or write to the file."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<filename>sssd.conf</filename> は、root により所有され、root のみが読み書きで"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"きる、通常のファイルである必要があります。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The configuration file <filename>sssd.conf</filename> will include "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"configuration snippets using the include directory <filename>conf.d</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"filename>. This feature is available if SSSD was compiled with libini "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"version 1.3.0 or later."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Any file placed in <filename>conf.d</filename> that ends in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote><filename>.conf</filename></quote> and does not begin with a dot "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"to configure SSSD."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The configuration snippets from <filename>conf.d</filename> have higher "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"priority than <filename>sssd.conf</filename> and will override "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<filename>sssd.conf</filename> when conflicts occur. If several snippets are "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"present in <filename>conf.d</filename>, then they are included in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"alphabetical order (based on locale). Files included later have higher "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"priority. Numerical prefixes (<filename>01_snippet.conf</filename>, "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<filename>02_snippet.conf</filename> etc.) can help visualize the priority "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"(higher number means higher priority)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The snippet files require the same owner and permissions as <filename>sssd."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"conf</filename>. Which are by default root:root and 0600."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "GENERAL OPTIONS"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Following options are usable in more than one configuration sections."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Options usable in all sections"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "debug_level (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "debug_level (整数)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"for <replaceable>debug_level</replaceable> as a convenience feature. If both "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are specified, the value of <replaceable>debug_level</replaceable> will be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_timestamps (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "debug_timestamps (論理値)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Add a timestamp to the debug messages. If journald is enabled for SSSD "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"debug logging this option is ignored."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:133 sssd.conf.5.xml:543 sssd.conf.5.xml:837
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1467 sssd-ldap.5.xml:1722 sssd-ldap.5.xml:1819
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:1881 sssd-ldap.5.xml:2447 sssd-ldap.5.xml:2512
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:2530 sssd-ad.5.xml:211 sssd-ad.5.xml:325 sssd-ad.5.xml:862
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:499 sssd-secrets.5.xml:351 sssd-secrets.5.xml:364
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: true"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: true"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "debug_microseconds (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "debug_microseconds (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Add microseconds to the timestamp in debug messages. If journald is enabled "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for SSSD debug logging this option is ignored."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:146 sssd.conf.5.xml:540 sssd.conf.5.xml:721
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:1400 sssd.conf.5.xml:2865 sssd-ldap.5.xml:708
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:1596 sssd-ldap.5.xml:1615 sssd-ldap.5.xml:1791
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:2217 sssd-ipa.5.xml:145 sssd-ipa.5.xml:232
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd-ipa.5.xml:540 sssd-krb5.5.xml:266 sssd-krb5.5.xml:300
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: false"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: false"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:106 sssd.conf.5.xml:157 sssd-ldap.5.xml:2255
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-systemtap.5.xml:82 sssd-systemtap.5.xml:143 sssd-systemtap.5.xml:210
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-systemtap.5.xml:248 sssd-systemtap.5.xml:304
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "<placeholder type=\"variablelist\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Options usable in SERVICE and DOMAIN sections"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "timeout (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Timeout in seconds between heartbeats for this service. This is used to "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ensure that the process is alive and capable of answering requests. Note "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that after three missed heartbeats the process will terminate itself."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:169 sssd.conf.5.xml:1352 sssd.conf.5.xml:2881
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:1467 include/ldap_id_mapping.xml:264
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 10"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 10"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SPECIAL SECTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "特別セクション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The [sssd] section"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "[sssd] セクション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:191 sssd.conf.5.xml:2970
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Section parameters"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "セクションのパラメーター"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "config_file_version (integer)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "config_file_version (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Indicates what is the syntax of the config file. SSSD 0.6.0 and later use "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"設定ファイルの構文が何であるカを指示します。SSSD 0.6.0 およびそれ以降はバー"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ジョン 2 を使用します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "services"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "services"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Comma separated list of services that are started when sssd itself starts. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<phrase condition=\"have_systemd\"> The services' list is optional on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"platforms where systemd is supported, as they will either be socket or dbus "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"activated when needed. </phrase>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</phrase> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<phrase condition=\"with_autofs\">, autofs</phrase> <phrase condition="
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"with_ssh\">, ssh</phrase> <phrase condition=\"with_pac_responder\">, pac</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"phrase> <phrase condition=\"with_ifp\">, ifp</phrase>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"<phrase condition=\"have_systemd\"> By default, all services are disabled "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"and the administrator must enable the ones allowed to be used by executing: "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"\"systemctl enable sssd-@service@.socket\". </phrase>"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "reconnection_retries (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "reconnection_retries (整数)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Number of times services should attempt to reconnect in the event of a Data "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Provider crash or restart before they give up"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"データプロバイダーがクラッシュまたは再起動した場合、サービスが再接続をあきら"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"める前に試行する回数です。"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Default: 3"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 3"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "domains"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "domains"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"A domain is a database containing user information. SSSD can use more "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"domains at the same time, but at least one must be configured or SSSD won't "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"start. This parameter describes the list of domains in the order you want "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"them to be queried. A domain name should only consist of alphanumeric ASCII "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"characters, dashes, dots and underscores."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:259 sssd.conf.5.xml:2508
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "re_expression (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "re_expression (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Default regular expression that describes how to parse the string containing "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"user name and domain into these components."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Each domain can have an individual regular expression configured. For some "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ID providers there are also default regular expressions. See DOMAIN SECTIONS "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for more info on these regular expressions."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:276 sssd.conf.5.xml:2559
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "full_name_format (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "full_name_format (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd.conf.5.xml:279 sssd.conf.5.xml:2562
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum> </citerefentry>-compatible format that describes how to compose a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"fully qualified name from user name and domain name components."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ユーザー名とドメイン名のコンポーネントから完全修飾名を表現する方法を表す "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum> </citerefentry> 互換形式。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:290 sssd.conf.5.xml:2573
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd.conf.5.xml:291 sssd.conf.5.xml:2574
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "user name"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:294 sssd.conf.5.xml:2577
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "domain name as specified in the SSSD config file."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SSSD 設定ファイルにおいて指定されるドメイン名。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:303 sssd.conf.5.xml:2586
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"domain flat name. Mostly usable for Active Directory domains, both directly "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"configured or discovered via IPA trusts."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:287 sssd.conf.5.xml:2570
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following expansions are supported: <placeholder type=\"variablelist\" "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"以下の拡張モジュールがサポートされます: <placeholder type=\"variablelist\" "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Each domain can have an individual format string configured. see DOMAIN "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SECTIONS for more info on this option."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "try_inotify (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "try_inotify (論理値)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"SSSD monitors the state of resolv.conf to identify when it needs to update "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"its internal DNS resolver. By default, we will attempt to use inotify for "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"this, and will fall back to polling resolv.conf every five seconds if "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"inotify cannot be used."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"SSSD は、内部 DNS リゾルバーを更新する必要となるときを認識するために、resolv."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"conf の状態を監視します。初期状態では、このために inotify を使用しようとしま"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"す。inotify が使用できない場合 5 秒ごとに resolv.conf をポーリングするよう"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"フォールバックします。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"There are some limited situations where it is preferred that we should skip "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"even trying to use inotify. In these rare cases, this option should be set "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"inotify を使用することをスキップすることが望ましい、いくつかの制限された状況"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"があります。これらの珍しい場合では、このオプションが 'false' に設定されるべき"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Default: true on platforms where inotify is supported. False on other "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"初期値: inotify がサポートされるプラットフォームにおいては真です。他のプラッ"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"トフォームにおいては偽です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: this option will have no effect on platforms where inotify is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"unavailable. On these platforms, polling will always be used."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"注: このオプションは inotify が利用不可能なプラットフォームにおいて効果があり"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ません。これらのプラットフォームにおいては、ポーリングが常に使用されます。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "krb5_rcache_dir (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "krb5_rcache_dir (文字列)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Directory on the filesystem where SSSD should store Kerberos replay cache "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"SSSD が Kerberos リプレイキャッシュファイルを保存するファイルシステムのディレ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"SSSD to let libkrb5 decide the appropriate location for the replay cache."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"このオプションは、libkrb5 がリプレイキャッシュに対する適切な場所を決められる"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"よう SSSD に指示する、特別な値 __LIBKRB5_DEFAULTS__ を受け付けます。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Default: Distribution-specific and specified at build-time. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"(__LIBKRB5_DEFAULTS__ if not configured)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"初期値: ディストリビューション固有かつ構築時に指定されます。 (設定されていな"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ければ __LIBKRB5_DEFAULTS__ です)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "user (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The user to drop the privileges to where appropriate to avoid running as the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"root user. <phrase condition=\"have_systemd\"> This option does not work "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"when running socket-activated services, as the user set up to run the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"processes is set up during compilation time. The way to override the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"systemd unit files is by creating the appropriate files in /etc/systemd/"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"system/. Keep in mind that any change in the socket user, group or "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"permissions may result in a non-usable SSSD. The same may occur in case of "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"changes of the user running the NSS responder. </phrase>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: not set, process will run as root"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "default_domain_suffix (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "default_domain_suffix (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This string will be used as a default domain name for all names without a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"domain name component. The main use case is environments where the primary "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"domain is intended for managing host policies and all users are located in a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"trusted domain. The option allows those users to log in just with their "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"user name without giving a domain name as well."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that if this option is set all users from the primary domain "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"have to use their fully qualified name, e.g. user@domain.name, to log in. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Setting this option changes default of use_fully_qualified_names to True. It "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is not allowed to use this option together with use_fully_qualified_names "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"set to False."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:418 sssd.conf.5.xml:1156 sssd-ldap.5.xml:679
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1555 sssd-ldap.5.xml:1567 sssd-ldap.5.xml:1649
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:667 sssd-ad.5.xml:742 sssd-krb5.5.xml:410 sssd-krb5.5.xml:556
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-secrets.5.xml:339 sssd-secrets.5.xml:377 sssd-secrets.5.xml:390
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-secrets.5.xml:404 sssd-secrets.5.xml:415
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:205 include/ldap_id_mapping.xml:216
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: not set"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 設定されません"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "override_space (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This parameter will replace spaces (space bar) with the given character for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"user and group names. e.g. (_). User name "john doe" will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek""john_doe" This feature was added to help compatibility with shell "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"scripts that have difficulty handling spaces, due to the default field "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"separator in the shell."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note it is a configuration error to use a replacement character that "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"might be used in user or group names. If a name contains the replacement "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"character SSSD tries to return the unmodified name but in general the result "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"of a lookup is undefined."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: not set (spaces will not be replaced)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "certificate_verification (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "no_ocsp"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Disables Online Certificate Status Protocol (OCSP) checks. This might be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"needed if the OCSP servers defined in the certificate are not reachable from "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "no_verification"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Disables verification completely. This option should only be used for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ocsp_default_responder=URL"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Sets the OCSP default responder which should be used instead of the one "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"mentioned in the certificate. URL must be replaced with the URL of the OCSP "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"default responder e.g. http://example.com:80/ocsp."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option must be used together with ocsp_default_responder_signing_cert."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ocsp_default_responder_signing_cert=NAME"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The nickname of the cert to trust (expected) to sign the OCSP responses. "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The certificate with the given nickname must be available in the systems NSS "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "This option must be used together with ocsp_default_responder."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"With this parameter the certificate verification can be tuned with a comma "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"separated list of options. Supported options are: <placeholder type="
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"variablelist\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Unknown options are reported but ignored."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: not set, i.e. do not restrict certificate verification"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "disable_netlink (boolean)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"SSSD hooks into the netlink interface to monitor changes to routes, "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"addresses, links and trigger certain actions."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The SSSD state changes caused by netlink events may be undesirable and can "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"be disabled by setting this option to 'true'"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: false (netlink changes are detected)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "enable_files_domain (boolean)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"When this option is enabled, SSSD prepends an implicit domain with "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>id_provider=files</quote> before any explicitly configured domains."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "domain_resolution_order"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Comma separated list of domains and subdomains representing the lookup order "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"that will be followed. The list doesn't have to include all possible "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domains as the missing domains will be looked up based on the order they're "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"presented in the <quote>domains</quote> configuration option. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"subdomains which are not listed as part of <quote>lookup_order</quote> will "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"be looked up in a random order for each parent domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please, note that when this option is set the output format of all commands "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"is always fully-qualified even when using short names for input. In case "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the administrator wants the output not fully-qualified, the full_name_format "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"option can be used as shown below: <quote>full_name_format=%1$s</quote> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"However, keep in mind that during login, login applications often "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"canonicalize the username by calling <citerefentry> <refentrytitle>getpwnam</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>3</manvolnum> </citerefentry> which, if a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"shortname is returned for a qualified input (while trying to reach a user "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"which exists in multiple domains) might re-route the login attempt into the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domain which users shortnames, making this workaround totally not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"recommended in cases where usernames may overlap between domains."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:587 sssd.conf.5.xml:1364 sssd.conf.5.xml:2931
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ad.5.xml:148 sssd-ad.5.xml:286 sssd-ad.5.xml:300
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Not set"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Individual pieces of SSSD functionality are provided by special SSSD "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"services that are started and stopped together with SSSD. The services are "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"managed by a special service frequently called <quote>monitor</quote>. The "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>[sssd]</quote> section is used to configure the monitor as well as "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"some other important options like the identity domains. <placeholder type="
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD の機能の各部分は SSSD と一緒に開始および停止される特別な SSSD サービスに"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"より提供されます。特別なサービスにより管理されるサービスはよく<quote>モニター"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"</quote>と呼ばれます。<quote>[sssd]</quote> セクションは、モニターだけでな"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"く、識別ドメインのような他の重要なオプションを設定するために使用されます。 "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SERVICES SECTIONS"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "サービスセクション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Settings that can be used to configure different services are described in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this section. They should reside in the [<replaceable>$NAME</replaceable>] "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"section, for example, for NSS service, the section would be <quote>[nss]</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"異なるサービスを設定するために使用される設定がこのセクションに記述されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"それらは [<replaceable>$NAME</replaceable>] セクションに置かれます。たとえ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ば、NSS サービスは <quote>[nss]</quote> セクションです"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "General service configuration options"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "サービス設定の全体オプション"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "These options can be used to configure any service."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "これらのオプションはすべてのサービスを設定するために使用できます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "fd_limit"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "fd_limit"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option specifies the maximum number of file descriptors that may be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"opened at one time by this SSSD process. On systems where SSSD is granted "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"systems without this capability, the resulting value will be the lower value "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of this or the limits.conf \"hard\" limit."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 8192 (or limits.conf \"hard\" limit)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "client_idle_timeout"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "client_idle_timeout"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option specifies the number of seconds that a client of an SSSD process "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"can hold onto a file descriptor without communicating on it. This value is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"limited in order to avoid resource exhaustion on the system. The timeout "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"can't be shorter than 10 seconds. If a lower value is configured, it will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"adjusted to 10 seconds."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:655 sssd.conf.5.xml:687 sssd.conf.5.xml:968
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 60"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 60"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "offline_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When SSSD switches to offline mode the amount of time before it tries to go "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"back online will increase based upon the time spent disconnected. This "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"value is in seconds and calculated by the following:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "offline_timeout + random_offset"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The random offset can increment up to 30 seconds. After each unsuccessful "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"attempt to go online, the new interval is recalculated by the following:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "new_interval = old_interval*2 + random_offset"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note that the maximum length of each interval is currently limited to one "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"hour. If the calculated length of new_interval is greater than an hour, it "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"will be forced to one hour."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "responder_idle_timeout"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"This option specifies the number of seconds that an SSSD responder process "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"can be up without being used. This value is limited in order to avoid "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"resource exhaustion on the system. The minimum acceptable value for this "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"option is 60 seconds. Setting this option to 0 (zero) means that no timeout "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"will be set up to the responder. This option only has effect when SSSD is "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"built with systemd support and when services are either socket or dbus "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.conf.5.xml:709 sssd.conf.5.xml:980 sssd.conf.5.xml:1559
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Default: 300"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "初期値: 300"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "cache_first"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"This option specifies whether the responder should query all caches before "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"querying the Data Providers."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "NSS configuration options"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "NSS 設定オプション"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"These options can be used to configure the Name Service Switch (NSS) service."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"これらのオプションは Name Service Switch (NSS) サービスを設定するために使用で"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "enum_cache_timeout (integer)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "enum_cache_timeout (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"How many seconds should nss_sss cache enumerations (requests for info about "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"nss_sss が列挙をキャッシュする秒数です(すべてのユーザーに関する情報に対する"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 120"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "初期値: 120"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "entry_cache_nowait_percentage (integer)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "entry_cache_nowait_percentage (整数)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"The entry cache can be set to automatically update entries in the background "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"if they are requested beyond a percentage of the entry_cache_timeout value "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"for the domain."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"エントリーキャッシュは、ドメインに対して entry_cache_timeout の値を超えて要求"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"された場合に、バックグラウンドでエントリーを自動的に更新するよう設定できま"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"For example, if the domain's entry_cache_timeout is set to 30s and "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"entry_cache_nowait_percentage is set to 50 (percent), entries that come in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"after 15 seconds past the last cache update will be returned immediately, "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"but the SSSD will go and update the cache on its own, so that future "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"requests will not need to block waiting for a cache update."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"たとえば、ドメインの entry_cache_timeout が 30s に設定され、"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"entry_cache_nowait_percentage が 50 (%) に設定されていると、エントリーが 15 "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"秒経過後にきて、最新の更新キャッシュが直ちに返されます。しかし、SSSD が自身に"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"キャッシュされ、更新されます。そのため、その先の要求はキャッシュ更新を待つこ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"とをブロックする必要がありません。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Valid values for this option are 0-99 and represent a percentage of the "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"entry_cache_timeout for each domain. For performance reasons, this "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"percentage will never reduce the nowait timeout to less than 10 seconds. (0 "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"disables this feature)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"このオプションに対して有効な値は 0-99 です。各ドメインに対する "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"entry_cache_timeout のパーセンテージを表します。性能上の理由から、このパーセ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ンテージは 10 秒よりも小さく nowait タイムアウトを減らすべきではありません。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"(0 はこの機能を無効にします)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd.conf.5.xml:775 sssd.conf.5.xml:1421
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 50"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "初期値: 50"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "entry_negative_timeout (integer)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "entry_negative_timeout (整数)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Specifies for how many seconds nss_sss should cache negative cache hits "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"(that is, queries for invalid database entries, like nonexistent ones) "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"before asking the back end again."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"nss_sss が再びバックエンドに問い合わせる前にネガティブキャッシュヒット(つま"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"り、存在しないドメインのように、無効なデータベースエントリーに対する問い合わ"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"せ)をキャッシュする秒数を指定します。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd.conf.5.xml:789 sssd.conf.5.xml:1445
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 15"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "初期値: 15"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "local_negative_timeout (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies for how many seconds nss_sss should keep local users and groups in "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"negative cache before trying to look it up in the back end again."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: sssd.conf.5.xml:802 sssd.conf.5.xml:1210 sssd.conf.5.xml:2815 sssd.8.xml:79
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 0"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: 0"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "filter_users, filter_groups (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "filter_users, filter_groups (文字列)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Exclude certain users or groups from being fetched from the sss NSS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"database. This is particularly useful for system accounts. This option can "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"also be set per-domain or include fully-qualified names to filter only users "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"from the particular domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"NOTE: The filter_groups option doesn't affect inheritance of nested group "
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"members, since filtering happens after they are propagated for returning via "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"NSS. E.g. a group having a member group filtered out will still have the "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"member users of the latter listed."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: root"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "初期値: root"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "filter_users_in_groups (bool)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "filter_users_in_groups (論理値)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If you want filtered user still be group members set this option to false."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"フィルターされたユーザーがまだグループメンバーのままにしたいならば、このオプ"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ションを偽に設定します。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "fallback_homedir (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "fallback_homedir (文字列)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Set a default template for a user's home directory if one is not specified "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"explicitly by the domain's data provider."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ドメインのデータプロバイダーにより明示的に指定されていない場合に、ユーザーの"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ホームディレクトリーの標準テンプレートを設定します。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The available values for this option are the same as for override_homedir."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"このオプションに対して利用可能なオプションは override_homedir に対するものと"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"fallback_homedir = /home/%u\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"fallback_homedir = /home/%u\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:856 sssd.conf.5.xml:1289 sssd.conf.5.xml:1308
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:539 include/override_homedir.xml:59
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "example: <placeholder type=\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "例: <placeholder type=\"programlisting\" id=\"0\"/>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set (no substitution for unset home directories)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 設定なし (ホームディレクトリーの設定がない場合は代替なし)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "override_shell (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "override_shell (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Override the login shell for all users. This option supersedes any other "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"shell options if it takes effect and can be set either in the [nss] section "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"or per-domain."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set (SSSD will use the value retrieved from LDAP)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 設定なし (SSSD は LDAP から取得された値を使用します)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "allowed_shells (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "allowed_shells (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Restrict user shell to one of the listed values. The order of evaluation is:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ユーザーのシェルを一覧にある値のどれかに制限します。評価の順番は次のとおりで"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"1. シェルが <quote>/etc/shells</quote> に存在すると、それが使用されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"quote>, use the value of the shell_fallback parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"2. シェルが allowed_shells 一覧にあるが、<quote>/etc/shells</quote> になけれ"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"ば、shell_fallback パラメーターの値を使用します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"3. If the shell is not in the allowed_shells list and not in <quote>/etc/"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"shells</quote>, a nologin shell is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"3. シェルが allowed_shells 一覧になく、<quote>/etc/shells</quote> にもなけれ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ば、nologin シェルが使用されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The wildcard (*) can be used to allow any shell."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The (*) is useful if you want to use shell_fallback in case that user's "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"shell is not in <quote>/etc/shells</quote> and maintaining list of all "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"allowed shells in allowed_shells would be to much overhead."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "An empty string for shell is passed as-is to libc."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "シェルの空文字列は libc にそのまま渡されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The <quote>/etc/shells</quote> is only read on SSSD start up, which means "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"that a restart of the SSSD is required in case a new shell is installed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>/etc/shells</quote> は SSSD が開始されるときにのみ読み込まれます。これ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"は新しいシェルがインストールされた場合 SSSD の再起動が必要になることを意味し"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Not set. The user shell is automatically used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "初期値: 設定されません。ユーザーシェルが自動的に使用されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "vetoed_shells (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "vetoed_shells (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Replace any instance of these shells with the shell_fallback"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "これらのシェルのインスタンスをすべて shell_fallback に置き換えます"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "shell_fallback (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "shell_fallback (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The default shell to use if an allowed shell is not installed on the machine."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"許可されたシェルがマシンにインストールされていない場合に使用する標準シェルで"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: /bin/sh"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "default_shell"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "default_shell"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The default shell to use if the provider does not return one during lookup. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option can be specified globally in the [nss] section or per-domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Default: not set (Return NULL if no shell is specified and rely on libc to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"substitute something sensible when necessary, usually /bin/sh)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd.conf.5.xml:961 sssd.conf.5.xml:1215
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "get_domains_timeout (int)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "get_domains_timeout (整数)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd.conf.5.xml:964 sssd.conf.5.xml:1218
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies time in seconds for which the list of subdomains will be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"considered valid."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "memcache_timeout (int)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "memcache_timeout (整数)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies time in seconds for which records in the in-memory cache will be "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"client applications will not use the fast in-memory cache."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "user_attributes (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Some of the additional NSS responder requests can return more attributes "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"than just the POSIX ones defined by the NSS interface. The list of "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"attributes is controlled by this option. It is handled the same way as the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<quote>user_attributes</quote> option of the InfoPipe responder (see "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"manvolnum> </citerefentry> for details) but with no default values."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"To make configuration more easy the NSS responder will check the InfoPipe "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"option if it is not set for the NSS responder."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: not set, fallback to InfoPipe option"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pwfield (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The value that NSS operations that return users or groups will return for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the <quote>password</quote> field."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1025 include/override_homedir.xml:56
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "This option can also be set per-domain."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "このオプションはドメインごとに設定できます。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Default: <quote>*</quote> (remote domains) or <quote>x</quote> (the files "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "PAM configuration options"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "PAM 設定オプション"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"These options can be used to configure the Pluggable Authentication Module "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"(PAM) service."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"これらのオプションは Pluggable Authentication Module (PAM) サービスを設定する"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "offline_credentials_expiration (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "offline_credentials_expiration (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If the authentication provider is offline, how long should we allow cached "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"logins (in days since the last successful online login)."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"認証プロバイダーがオフラインの場合に、キャッシュログインを許可する時間(オン"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ラインログインの最終成功からの日数)です。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 0 (No limit)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "初期値: 0 (無制限)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "offline_failed_login_attempts (integer)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "offline_failed_login_attempts (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If the authentication provider is offline, how many failed login attempts "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are allowed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"認証プロバイダーがオフラインの場合、ログイン試行の失敗が許容される回数です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "offline_failed_login_delay (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "offline_failed_login_delay (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The time in minutes which has to pass after offline_failed_login_attempts "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"has been reached before a new login attempt is possible."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"新しいログイン試行が可能になる前に offline_failed_login_attempts に達した後に"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"渡される分単位の時間です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If set to 0 the user cannot authenticate offline if "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"offline_failed_login_attempts has been reached. Only a successful online "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"authentication can enable offline authentication again."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"0 に設定されていると、offline_failed_login_attempts に達した場合、ユーザーが"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"オフライン認証できません。オンライン認証に成功すると、再びオフライン認証を有"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 5"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 5"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "pam_verbosity (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "pam_verbosity (整数)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Controls what kind of messages are shown to the user during authentication. "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The higher the number to more messages are displayed."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"認証中にユーザーに表示されるメッセージの種類を制御します。数字が大きければ大"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"きいほどメッセージが表示されます。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Currently sssd supports the following values:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "現在 sssd は以下の値をサポートします:"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<emphasis>0</emphasis>: do not show any message"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "<emphasis>0</emphasis>: 何もメッセージを表示しない"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<emphasis>1</emphasis>: show only important messages"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "<emphasis>1</emphasis>: 重要なメッセージのみを表示する"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<emphasis>2</emphasis>: show informational messages"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "<emphasis>2</emphasis>: 情報レベルのメッセージを表示する"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>3</emphasis>: show all messages and debug information"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "<emphasis>3</emphasis>: すべてのメッセージとデバッグ情報を表示する"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 1"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: 1"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_response_filter (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"A comma separated list of strings which allows to remove (filter) data sent "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"by the PAM responder to pam_sss PAM module. There are different kind of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"responses sent to pam_sss e.g. messages displayed to the user or environment "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"variables which should be set by pam_sss."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"While messages already can be controlled with the help of the pam_verbosity "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"option this option allows to filter out other kind of responses as well."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Do not send any environment variables to any service."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ENV:var_name"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Do not send environment variable var_name to any service."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ENV:var_name:service"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Do not send environment variable var_name to service."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Currently the following filters are supported: <placeholder type="
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"\"variablelist\" id=\"0\"/>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Example: ENV:KRB5CCNAME:sudo-i"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "pam_id_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "pam_id_timeout (整数)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"For any PAM request while SSSD is online, the SSSD will attempt to "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"immediately update the cached identity information for the user in order to "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"ensure that authentication takes place with the latest information."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"SSSD がオンラインの間はすべての PAM 要求に対して、ユーザーが最新の情報で認証"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"されるよう、SSSD は直ちにキャッシュされた識別情報を更新しようとします。"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"A complete PAM conversation may perform multiple PAM requests, such as "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"account management and session opening. This option controls (on a per-"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"client-application basis) how long (in seconds) we can cache the identity "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"information to avoid excessive round-trips to the identity provider."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"完全な PAM のやりとりは、アカウント管理やセッション開始のように、複数の PAM "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"要求を実行できます。このオプションは、識別プロバイダーに対する過剰なラウンド"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"トリップを避けるために識別情報をキャッシュできる時間(秒数)を(クライアント"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"アプリケーションごとに)制御します。"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_pwd_expiration_warning (integer)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "pam_pwd_expiration_warning (整数)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Display a warning N days before the password expires."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "パスワードの期限が切れる前に N 日間警告を表示します。"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that the backend server has to provide information about the "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"expiration time of the password. If this information is missing, sssd "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"cannot display a warning."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"バックエンドのサーバーがパスワードの有効期間に関する情報を提供する必要がある"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ことに注意してください。この情報がなければ、sssd は警告を表示します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If zero is set, then this filter is not applied, i.e. if the expiration "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"warning was received from backend server, it will automatically be displayed."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This setting can be overridden by setting <emphasis>pwd_expiration_warning</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"emphasis> for a particular domain."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "pam_trusted_users (string)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"allowed to run PAM conversations against trusted domains. Users not "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"included in this list can only access domains marked as public with "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<quote>pam_public_domains</quote>. User names are resolved to UIDs at "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: All users are considered trusted by default"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that UID 0 is always allowed to access the PAM responder even in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"case it is not in the pam_trusted_users list."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_public_domains (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the comma-separated list of domain names that are accessible even "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to untrusted users."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Two special values for pam_public_domains option are defined:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"all (Untrusted users are allowed to access all domains in PAM responder.)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"none (Untrusted users are not allowed to access any domains PAM in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1270 sssd.conf.5.xml:1295 sssd.conf.5.xml:1314
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sssd.conf.5.xml:1807 sssd.conf.5.xml:2751 sssd-ldap.5.xml:1850
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "Default: none"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr "初期値: none"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_account_expired_message (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Allows a custom expiration message to be set, replacing the default "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"'Permission denied' message."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Note: Please be aware that message is only printed for the SSH service "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"unless pam_verbosity is set to 3 (show all messages and debug information)."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"pam_account_expired_message = Account expired, please contact help desk.\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_account_locked_message (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Allows a custom lockout message to be set, replacing the default 'Permission "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"denied' message."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"pam_account_locked_message = Account locked, please contact help desk.\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pam_cert_auth (bool)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Enable certificate based Smartcard authentication. Since this requires "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"additional communication with the Smartcard which will delay the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"authentication process this option is disabled by default."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd.conf.5.xml:1328 sssd-ldap.5.xml:1078 sssd-ldap.5.xml:1105
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1396 sssd-ldap.5.xml:1417 sssd-ldap.5.xml:1923
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: False"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "初期値: 偽"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_cert_db_path (string)"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"The path to the certificate database which contain the PKCS#11 modules to "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"access the Smartcard."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "Default: /etc/pki/nssdb (NSS version)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "p11_child_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "How many seconds will pam_sss wait for p11_child to finish."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "pam_app_services (string)"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Which PAM services are permitted to contact domains of type "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>application</quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "SUDO configuration options"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SUDO 設定オプション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"These options can be used to configure the sudo service. The detailed "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"instructions for configuration of <citerefentry> <refentrytitle>sudo</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sudo_timed (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "sudo_timed (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"that implement time-dependent sudoers entries."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"時間依存の sudoers エントリーを実装する sudoNotBefore と sudoNotAfter の属性"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"を評価するかしないかです。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#| msgid "ldap_deref_threshold (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "sudo_threshold (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_deref_threshold (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Maximum number of expired rules that can be refreshed at once. If number of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"expired rules is below threshold, those rules are refreshed with "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<quote>rules refresh</quote> mechanism. If the threshold is exceeded a "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<quote>full refresh</quote> of sudo rules is triggered instead. This "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"threshold number also applies to IPA sudo command and command group searches."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "AUTOFS configuration options"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "Autofs 設定オプション"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "These options can be used to configure the autofs service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "これらのオプションが autofs サービスを設定するために使用されます。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "autofs_negative_timeout (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "autofs_negative_timeout (整数)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies for how many seconds should the autofs responder negative cache "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"hits (that is, queries for invalid map entries, like nonexistent ones) "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"before asking the back end again."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"autofs レスポンダーのネガティブキャッシュ(つまり、存在しないもののように、無"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"効なマップエントリーに対する問い合わせ)が再びバックエンドに問い合わせる前に"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ヒットする秒数を指定します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "SSH configuration options"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "SSH 設定オプション"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "These options can be used to configure the SSH service."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "これらのオプションは SSH サービスを設定するために使用されます。"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ssh_hash_known_hosts (bool)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ssh_hash_known_hosts (論理値)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Whether or not to hash host names and addresses in the managed known_hosts "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ssh_known_hosts_timeout (integer)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "ssh_known_hosts_timeout (整数)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"How many seconds to keep a host in the managed known_hosts file after its "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"host keys were requested."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 180"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "初期値: 180"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ca_db (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Path to a storage of trusted CA certificates. The option is used to validate "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"user certificates before deriving public ssh keys from them."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Default: /etc/pki/nssdb"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "PAC responder configuration options"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"The PAC responder works together with the authorization data plugin for MIT "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"PAC data during a GSSAPI authentication to the PAC responder. The sub-domain "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"provider collects domain SID and ID ranges of the domain the client is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"joined to and of remote trusted domains from the local domain controller. If "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the PAC is decoded and evaluated some of the following operations are done:"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"If the remote user does not exist in the cache, it is created. The UID is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"determined with the help of the SID, trusted domains will have UPGs and the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"GID will have the same value as the UID. The home directory is set based on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the subdomain_homedir parameter. The shell will be empty by default, i.e. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the system defaults are used, but can be overwritten with the default_shell "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If there are SIDs of groups from domains sssd knows about, the user will be "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"added to those groups."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "These options can be used to configure the PAC responder."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "allowed_uids (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "allowed_uids (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"allowed to access the PAC responder. User names are resolved to UIDs at "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: 0 (only the root user is allowed to access the PAC responder)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that although the UID 0 is used as the default it will be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"overwritten with this option. If you still want to allow the root user to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access the PAC responder, which would be the typical case, you have to add 0 "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to the list of allowed UIDs as well."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "pac_lifetime (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"data can be used to determine the group memberships of a user."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#| msgid "General service configuration options"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Session recording configuration options"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "サービス設定の全体オプション"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#| "This manual page describes the configuration of the IPA provider for "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#| "<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#| "manvolnum> </citerefentry>. For a detailed syntax reference, refer to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#| "the <quote>FILE FORMAT</quote> section of the <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "citerefentry> manual page."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Session recording works in conjunction with <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>tlog-rec-session</refentrytitle> <manvolnum>8</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry>, a part of tlog package, to log what users see and type when "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"they log in on a text terminal. See also <citerefentry> <refentrytitle>sssd-"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"session-recording</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"このマニュアルページは <citerefentry> <refentrytitle>sssd</refentrytitle> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<manvolnum>8</manvolnum> </citerefentry> に対する IPA プロバイダーの設定を説"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"明しています。詳細な構文の参考資料は <citerefentry> <refentrytitle>sssd."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> マニュアルペー"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ジの <quote>ファイル形式</quote> を参照してください。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "These options can be used to configure any service."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "These options can be used to configure session recording."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "これらのオプションはすべてのサービスを設定するために使用できます。"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.conf.5.xml:1586 sssd-session-recording.5.xml:64
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#| msgid "sudo_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "scope (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "sudo_provider (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1593 sssd-session-recording.5.xml:71
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "\"none\""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.conf.5.xml:1596 sssd-session-recording.5.xml:74
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "No users are recorded."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1601 sssd-session-recording.5.xml:79
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "\"some\""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:1604 sssd-session-recording.5.xml:82
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "Append this user to groups specified by the <replaceable>GROUPS</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "is a comma separated list of group names."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Users/groups specified by <replaceable>users</replaceable> and "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<replaceable>groups</replaceable> options are recorded."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"このユーザーを <replaceable>GROUPS</replaceable> パラメーターにより指定された"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"グループに追加します。 <replaceable>GROUPS</replaceable> パラメーターはグルー"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"プ名のカンマ区切り一覧です。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1613 sssd-session-recording.5.xml:91
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "\"all\""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:1616 sssd-session-recording.5.xml:94
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "All users are recorded."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#: sssd.conf.5.xml:1589 sssd-session-recording.5.xml:67
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#| "The following expansions are supported: <placeholder type=\"variablelist"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#| "\" id=\"0\"/>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"One of the following strings specifying the scope of session recording: "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"以下の拡張モジュールがサポートされます: <placeholder type=\"variablelist\" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd.conf.5.xml:1623 sssd-session-recording.5.xml:101
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#| msgid "Default: none"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: \"none\""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: none"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd.conf.5.xml:1628 sssd-session-recording.5.xml:106
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "skel_dir (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "users (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "skel_dir (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd.conf.5.xml:1631 sssd-session-recording.5.xml:109
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"A comma-separated list of users which should have session recording enabled. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Matches user names as returned by NSS. I.e. after the possible space "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"replacement, case changes, etc."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd.conf.5.xml:1637 sssd-session-recording.5.xml:115
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#| msgid "Default: empty, i.e. ldap_uri is used."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: Empty. Matches no users."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "初期値: 空、つまり ldap_uri が使用されます。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1642 sssd-session-recording.5.xml:120
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "ldap_group_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "groups (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_group_name (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:1645 sssd-session-recording.5.xml:123
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A comma-separated list of groups, members of which should have session "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"recording enabled. Matches group names as returned by NSS. I.e. after the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"possible space replacement, case changes, etc."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd.conf.5.xml:1651 sssd-session-recording.5.xml:129
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"NOTE: using this option (having it set to anything) has a considerable "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"performance cost, because each uncached request for a user requires "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"retrieving and matching the groups the user is member of."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd.conf.5.xml:1658 sssd-session-recording.5.xml:136
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: Empty. Matches no groups."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "DOMAIN SECTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ドメインセクション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "domain_type (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies whether the domain is meant to be used by POSIX-aware clients such "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"as the Name Service Switch or by applications that do not need POSIX data to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"be present or generated. Only objects from POSIX domains are available to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the operating system interfaces and utilities."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Allowed values for this option are <quote>posix</quote> and "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>application</quote>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"POSIX domains are reachable by all services. Application domains are only "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"reachable from the InfoPipe responder (see <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry>) and the PAM responder."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"NOTE: The application domains are currently well tested with "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>id_provider=ldap</quote> only."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For an easy way to configure a non-POSIX domains, please see the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>Application domains</quote> section."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: posix"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "min_id,max_id (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "min_id,max_id (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"UID and GID limits for the domain. If a domain contains an entry that is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"outside these limits, it is ignored."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ドメインに対する UID と GID の制限です。ドメインがこれらの制限の外にあるエン"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"トリーを含む場合、それは無視されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"For users, this affects the primary GID limit. The user will not be returned "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to NSS if either the UID or the primary GID is outside the range. For non-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"primary group memberships, those that are in range will be reported as "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ユーザーに対して、これはプライマリー GID 制限に影響します。 UID またはプライ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"マリー GID が範囲外ならば、ユーザーは NSS に返されません。非プライマリーメン"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"バーに対して、範囲内にあるものは予期されたものとして報告されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"These ID limits affect even saving entries to cache, not only returning them "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"by name or ID."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 1 for min_id, 0 (no limit) for max_id"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: min_id は 1, max_id は 0 (無制限)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "enumerate (bool)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "enumerate (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Determines if a domain can be enumerated. This parameter can have one of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"following values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ドメインが列挙できるかを決定します。このパラメーターは以下の値のどれかである"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "TRUE = Users and groups are enumerated"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "TRUE = ユーザーとグループが列挙されます"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FALSE = No enumerations for this domain"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "FALSE = このドメインに対して列挙しません"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd.conf.5.xml:1750 sssd.conf.5.xml:1965 sssd.conf.5.xml:2132
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: FALSE"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: FALSE"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Note: Enabling enumeration has a moderate performance impact on SSSD while "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"enumeration is running. It may take up to several minutes after SSSD startup "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"to fully complete enumerations. During this time, individual requests for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"information will go directly to LDAP, though it may be slow, due to the "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"heavy enumeration processing. Saving a large number of entries to cache "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"after the enumeration completes might also be CPU intensive as the "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"memberships have to be recomputed."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"While the first enumeration is running, requests for the complete user or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"group lists may return no results until it completes."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"最初の列挙が実行中の間、完全なユーザーまたはグループの一覧に対する要求は、そ"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"れが完了するまで結果を返しません。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Further, enabling enumeration may increase the time necessary to detect "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"network disconnection, as longer timeouts are required to ensure that "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"enumeration lookups are completed successfully. For more information, refer "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"to the man pages for the specific id_provider in use."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"さらに、列挙を有効にすることにより、挙の検索が確実に正しく完了するよりも長く"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"する必要があるので、ネットワーク切断を検知するために必要な時間が増える可能性"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"があります。詳細は使用している具体的な id_provider のマニュアルページを参照し"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"For the reasons cited above, enabling enumeration is not recommended, "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"especially in large environments."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "subdomain_enumerate (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "All discovered trusted domains will be enumerated"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "No discovered trusted domains will be enumerated"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Whether any of autodetected trusted domains should be enumerated. The "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"supported values are: <placeholder type=\"variablelist\" id=\"0\"/> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Optionally, a list of one or more domain names can enable enumeration just "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"for these trusted domains."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_timeout (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "entry_cache_timeout (整数)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"How many seconds should nss_sss consider entries valid before asking the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"backend again"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"nss_sss が再びバックエンドに問い合わせる前にエントリーを有効であると考える秒"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The cache expiration timestamps are stored as attributes of individual "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"objects in the cache. Therefore, changing the cache timeout only has effect "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"for newly added or expired entries. You should run the <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> tool in order to force refresh of entries that have already "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: 5400"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 5400"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "entry_cache_user_timeout (integer)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "entry_cache_user_timeout (整数)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"How many seconds should nss_sss consider user entries valid before asking "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the backend again"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"nss_sss が再びバックエンドに問い合わせる前にユーザーエントリーを有効であると"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd.conf.5.xml:1846 sssd.conf.5.xml:1859 sssd.conf.5.xml:1872
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd.conf.5.xml:1885 sssd.conf.5.xml:1898 sssd.conf.5.xml:1912
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: entry_cache_timeout"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: entry_cache_timeout"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "entry_cache_group_timeout (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "entry_cache_group_timeout (整数)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"How many seconds should nss_sss consider group entries valid before asking "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the backend again"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"nss_sss が再びバックエンドに問い合わせる前にグループエントリーを有効であると"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "entry_cache_netgroup_timeout (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "entry_cache_netgroup_timeout (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"How many seconds should nss_sss consider netgroup entries valid before "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"asking the backend again"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"nss_sss が再びバックエンドに問い合わせる前にネットワークグループエントリーを"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"有効であると考える秒数です。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "entry_cache_service_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "entry_cache_service_timeout (整数)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"How many seconds should nss_sss consider service entries valid before asking "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the backend again"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"nss_sss が再びバックエンドに問い合わせる前にサービスエントリーを有効であると"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "entry_cache_sudo_timeout (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "entry_cache_sudo_timeout (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"How many seconds should sudo consider rules valid before asking the backend "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "entry_cache_autofs_timeout (integer)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "entry_cache_autofs_timeout (整数)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"How many seconds should the autofs service consider automounter maps valid "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"before asking the backend again"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "entry_cache_ssh_host_timeout (integer)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"How many seconds to keep a host ssh key after refresh. IE how long to cache "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the host key for."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "refresh_expired_interval (integer)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr "refresh_expired_interval (整数)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Specifies how many seconds SSSD has to wait before triggering a background "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"refresh task which will refresh all expired or nearly expired records."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"The background refresh will process users, groups and netgroups in the cache."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "You can consider setting this value to 3/4 * entry_cache_timeout."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:1948 sssd-ldap.5.xml:746 sssd-ipa.5.xml:248
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: 0 (disabled)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "初期値: 0 (無効)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "cache_credentials (bool)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "cache_credentials (論理値)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Determines if user credentials are also cached in the local LDB cache"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ユーザーのクレディンシャルがローカル LDB キャッシュにキャッシュされるかどうか"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "User credentials are stored in a SHA512 hash, not in plaintext"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ユーザーのクレディンシャルが、平文ではなく SHA512 ハッシュで保存されます"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "cache_credentials_minimal_first_factor_length (int)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If 2-Factor-Authentication (2FA) is used and credentials should be saved "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this value determines the minimal length the first authentication factor "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"(long term password) must have to be saved as SHA512 hash into the cache."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This should avoid that the short PINs of a PIN based 2FA scheme are saved in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the cache which would make them easy targets for brute-force attacks."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: 8"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "account_cache_expiration (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "account_cache_expiration (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Number of days entries are left in cache after last successful login before "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"being removed during a cleanup of the cache. 0 means keep forever. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"value of this parameter must be greater than or equal to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"offline_credentials_expiration."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"正常にログイン後、キャッシュのクリーンアップ中にエントリーが削除される前の日"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"数です。 0 は永久に保持することを意味します。このパラメーターの値は "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"offline_credentials_expiration と同等以上でなければいけません。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 0 (unlimited)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 0 (無制限)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pwd_expiration_warning (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "pwd_expiration_warning (整数)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that the backend server has to provide information about the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"expiration time of the password. If this information is missing, sssd "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"cannot display a warning. Also an auth provider has to be configured for the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "Default: 7 (Kerberos), 0 (LDAP)"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr "初期値: 7 (Kerberos), 0 (LDAP)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "id_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "id_provider (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The identification provider used for the domain. Supported ID providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ドメインに対して使用される識別子プロバイダーです。サポートされる ID プロバイ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>proxy</quote>: Support a legacy NSS provider"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<quote>proxy</quote>: レガシーな NSS プロバイダーのサポート"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd.conf.5.xml:2041 sssd.conf.5.xml:2178
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgid "<quote>local</quote>: SSSD internal provider for local users"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "<quote>local</quote>: ローカルユーザー向け SSSD 内部プロバイダー"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"information on configuring LDAP."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<quote>ldap</quote>: LDAP プロバイダー。LDAP の設定に関する詳細は "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"manvolnum> </citerefentry> を参照してください。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd.conf.5.xml:2053 sssd.conf.5.xml:2158 sssd.conf.5.xml:2213
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"provider. See <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ipa</quote>: FreeIPA および Red Hat Enterprise Identity Management プ"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ロバイダー。FreeIPA の設定に関する詳細は <citerefentry> <refentrytitle>sssd-"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ipa</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> を参照してくださ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd.conf.5.xml:2062 sssd.conf.5.xml:2167 sssd.conf.5.xml:2222
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>ad</quote>: Active Directory provider. See <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry> for more information on configuring Active Directory."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>ad</quote>: Active Directory プロバイダー。Active Directory の設定に関"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"する詳細は <citerefentry> <refentrytitle>sssd-ad</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> を参照してください。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "use_fully_qualified_names (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "use_fully_qualified_names (論理値)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Use the full name and domain (as formatted by the domain's full_name_format) "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"as the user's login name reported to NSS."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"NSS に報告するユーザーのログイン名としてフルネームとドメイン (ドメインの完全"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"名形式により整形されたように) を使用します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"If set to TRUE, all requests to this domain must use fully qualified names. "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"For example, if used in LOCAL domain that contains a \"test\" user, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>getent passwd test</command> wouldn't find the user while "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>getent passwd test@LOCAL</command> would."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"TRUE に設定されていると、このドメインへのすべての要求は完全修飾名を使用する必"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"要があります。たとえば、 \"test\" ユーザーを含む LOCAL ドメインにおいて使用さ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"れていると、<command>getent passwd test</command> はユーザーを見つけられませ"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"んが、<command>getent passwd test@LOCAL</command> は見つけられます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: This option has no effect on netgroup lookups due to their tendency to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"include nested netgroups without qualified names. For netgroups, all domains "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"will be searched when an unqualified name is requested."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: FALSE (TRUE if default_domain_suffix is used)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ignore_group_members (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ignore_group_members (論理値)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Do not return group members for group lookups."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If set to TRUE, the group membership attribute is not requested from the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap server, and group members are not returned when processing group lookup "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"calls, such as <citerefentry> <refentrytitle>getgrnam</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>3</manvolnum> </citerefentry> or <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>getgrgid</refentrytitle> <manvolnum>3</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry>. As an effect, <quote>getent group $groupname</quote> would "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"return the requested group as if it was empty."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Enabling this option can also make access provider checks for group "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"membership significantly faster, especially for groups containing many "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "auth_provider (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "auth_provider (文字列)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The authentication provider used for the domain. Supported auth providers "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"ドメインに対して使用される認証プロバイダーです。サポートされる認証プロバイ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ダーは次のとおりです:"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ldap</quote> for native LDAP authentication. See <citerefentry> "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"citerefentry> for more information on configuring LDAP."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap</quote> は本来の LDAP 認証向けです。LDAP の設定に関する詳細は "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> を参照してください。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>krb5</quote> for Kerberos authentication. See <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more information on configuring Kerberos."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>krb5</quote> は Kerberos 認証向けです。Kerberos の設定に関する詳細は "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<citerefentry> <refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> を参照してください。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"<quote>proxy</quote> for relaying authentication to some other PAM target."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"<quote>proxy</quote> はいくつかの他の PAM ターゲットに認証を中継します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgid "<quote>none</quote> disables authentication explicitly."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "<quote>none</quote> は明示的に認証を無効化します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Default: <quote>id_provider</quote> is used if it is set and can handle "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"authentication requests."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"初期値: <quote>id_provider</quote> が設定され、認証要求を取り扱うことができる"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"ならば、それが使用されます。"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid "access_provider (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr "access_provider (文字列)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"The access control provider used for the domain. There are two built-in "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"access providers (in addition to any included in installed backends) "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Internal special providers are:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ドメインに対して使用されるアクセス制御プロバイダーです。 2 つの組み込みアクセ"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"スプロバイダーがあります(インストールされたバックエンドに含まれるすべてを加"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"えます)。内部の特別プロバイダーは次のとおりです:"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>permit</quote> always allow access. It's the only permitted access "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"provider for a local domain."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>permit</quote> は常にアクセスを許可します。ローカルドメインに対するプ"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"ロバイダーのみアクセスが許可されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>deny</quote> always deny access."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "<quote>deny</quote> は常にアクセスを拒否します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>simple</quote> access control based on access or deny lists. See "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum></citerefentry> for more information on configuring the simple "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access module."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>simple</quote> アクセス制御はアクセスまたは拒否の一覧に基づきます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"simple アクセスモジュールの設定に関する詳細は <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</manvolnum></"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> を参照してください。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>krb5</quote>: .k5login based access control. See <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> for more information on configuring Kerberos."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>proxy</quote> for relaying access control to another PAM module."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <quote>permit</quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: <quote>permit</quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "chpass_provider (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "chpass_provider (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The provider which should handle change password operations for the domain. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Supported change password providers are:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ドメインに対するパスワード変更操作を取り扱うプロバイダーです。サポートされる"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"パスワード変更プロバイダーは次のとおりです:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> to change a password stored in a LDAP server. See "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>krb5</quote> to change the Kerberos password. See <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> for more information on configuring Kerberos."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>krb5</quote> は Kerberos のパスワードを変更します。 Kerberos の設定に"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"関する詳細は <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> を参照してください。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>proxy</quote> for relaying password changes to some other PAM target."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>proxy</quote> はいくつかの他の PAM ターゲットにパスワードの変更を中継"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>none</quote> disallows password changes explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<quote>none</quote> は明示的にパスワードの変更を無効化します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: <quote>auth_provider</quote> is used if it is set and can handle "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"change password requests."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"初期値: <quote>auth_provider</quote> が設定され、パスワードの変更要求を取り扱"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"うことができるならば、それが使用されます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sudo_provider (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "sudo_provider (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "The SUDO provider used for the domain. Supported SUDO providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ドメインに使用される SUDO プロバイダーです。サポートされる SUDO プロバイダー"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> for more information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> は LDAP に保存されているルールのためです。LDAP の設定に関"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"する詳細は <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> を参照します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ad</quote> the same as <quote>ldap</quote> but with AD default "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>none</quote> disables SUDO explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<quote>none</quote> は SUDO を明示的に無効化します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:2333 sssd.conf.5.xml:2411 sssd.conf.5.xml:2476
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: The value of <quote>id_provider</quote> is used if it is set."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"初期値: <quote>id_provider</quote> の値が設定されていると使用されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The detailed instructions for configuration of sudo_provider are in the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry>. There are many configuration "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"options that can be used to adjust the behavior. Please refer to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry>."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "selinux_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "selinux_provider (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The provider which should handle loading of selinux settings. Note that this "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"provider will be called right after access provider ends. Supported selinux "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"providers are:"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ipa</quote> to load selinux settings from an IPA server. See "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "<quote>none</quote> disallows fetching selinux settings explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can handle "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"selinux loading requests."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "subdomains_provider (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "subdomains_provider (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The provider which should handle fetching of subdomains. This value should "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"be always the same as id_provider. Supported subdomain providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ipa</quote> to load a list of subdomains from an IPA server. See "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"manvolnum> </citerefentry> for more information on configuring IPA."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ad</quote> to load a list of subdomains from an Active Directory "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the AD provider."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>none</quote> disallows fetching subdomains explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<quote>none</quote> はサブドメインの取り出しを明示的に無効化します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "selinux_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "session_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "selinux_provider (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The provider which configures and manages user session related tasks. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"only user session task currently provided is the integration with Fleet "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Commander, which works only with IPA. Supported session providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>ipa</quote> to allow performing user session related tasks."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>none</quote> does not perform any kind of user session related tasks."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "Default: <quote>id_provider</quote> is used if it is set and can handle "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "authentication requests."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can perform "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"session related tasks."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"初期値: <quote>id_provider</quote> が設定され、認証要求を取り扱うことができる"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ならば、それが使用されます。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "autofs_provider (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "autofs_provider (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The autofs provider used for the domain. Supported autofs providers are:"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ドメインに対して使用される autofs プロバイダーです。 サポートされる autofs "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"プロバイダーは次のとおりです:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> for more information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> は LDAP に保存されているマップを読み込みます。LDAP の設定"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"に関する詳細は <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> を参照してください。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> for more information on configuring IPA."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ipa</quote> は IPA サーバーに保存されているマップを読み込みます。IPA "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"の設定に関する詳細は <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> を参照してください。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> for more information on configuring the AD provider."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "<quote>none</quote> disables autofs explicitly."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "<quote>none</quote> は明示的に autofs を無効にします。"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "hostid_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "hostid_provider (文字列)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"The provider used for retrieving host identity information. Supported "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"hostid providers are:"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"ホスト識別情報を取得するために使用されるプロバイダーです。 サポートされる "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"hostid プロバイダーは次のとおりです:"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"<quote>ipa</quote> to load host identity stored in an IPA server. See "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"<quote>ipa</quote> は IPA サーバーに保存されているホスト識別子を読み込みま"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"す。IPA の設定に関する詳細は <citerefentry> <refentrytitle>sssd-ipa</"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> を参照してください。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<quote>none</quote> disables hostid explicitly."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "<quote>none</quote> は明示的に hostid を無効にします。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Regular expression for this domain that describes how to parse the string "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"containing user name and domain into these components. The \"domain\" can "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"match either the SSSD configuration domain name, or, in the case of IPA "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"trust subdomains and Active Directory domains, the flat (NetBIOS) name of "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default for the AD and IPA provider: <quote>(((?P<domain>[^\\\\]+)\\"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"\\(?P<name>.+$))|((?P<name>[^@]+)@(?P<domain>.+$))|(^(?"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"P<name>[^@\\\\]+)$))</quote> which allows three different styles for "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "username"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "username"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "username@domain.name"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "username@domain.name"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "domain\\username"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr "domain\\username"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"While the first two correspond to the general default the third one is "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"introduced to allow easy integration of users from Windows domains."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Default: <quote>(?P<name>[^@]+)@?(?P<domain>[^@]*$)</quote> "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"which translates to \"the name is everything up to the <quote>@</quote> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"sign, the domain everything after that\""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"初期値: <quote>(?P<name>[^@]+)@?(?P<domain>[^@]*$)</quote> で"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"す。\"the name is everything up to the <quote>@</quote> sign, the domain "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"everything after that\" に解釈されます。"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"PLEASE NOTE: the support for non-unique named subpatterns is not available "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"on all platforms (e.g. RHEL5 and SLES10). Only platforms with libpcre "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"version 7 or higher can support non-unique named subpatterns."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"PLEASE NOTE ALSO: older version of libpcre only support the Python syntax (?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"P<name>) to label subpatterns."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"関連注記: 古いバージョンの libpcre はサブパターンをラベル付けするために "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Python 構文 (?P<name>) のみをサポートします。"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "Default: <quote>%1$s@%2$s</quote>."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr "初期値: <quote>%1$s@%2$s</quote>."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "lookup_family_order (string)"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr "lookup_family_order (文字列)"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Provides the ability to select preferred address family to use when "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"performing DNS lookups."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"DNS 検索を実行するときに使用する、優先アドレスファミリーを選択する機能を提供"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Supported values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "サポートする値:"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ipv4_first: IPv4 アドレスの検索を試行します。失敗すると IPv6 を試行します。"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ipv4_only: ホスト名を IPv4 アドレスに名前解決することのみを試行します。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ipv6_first: IPv6 アドレスの検索を試行します。失敗すると IPv4 を試行します。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ipv6_only: ホスト名を IPv6 アドレスに名前解決することのみを試行します。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: ipv4_first"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr "初期値: ipv4_first"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "dns_resolver_timeout (integer)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr "dns_resolver_timeout (整数)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| "Defines the amount of time (in seconds) to wait for a reply from the DNS "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| "resolver before assuming that it is unreachable. If this timeout is "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| "reached, the domain will continue to operate in offline mode."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Defines the amount of time (in seconds) to wait for a reply from the "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"internal fail over service before assuming that the service is unreachable. "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"If this timeout is reached, the domain will continue to operate in offline "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"DNS リゾルバーが到達不可能であると仮定するまでに、そこからの応答を待つ時間"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(秒単位)を定義します。このタイムアウトに達すると、ドメインはオフラインモー"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please see the section <quote>FAILOVER</quote> for more information about "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"the service resolution."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd.conf.5.xml:2648 sssd-ldap.5.xml:1278 sssd-ldap.5.xml:1320
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 6"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 6"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dns_discovery_domain (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "dns_discovery_domain (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If service discovery is used in the back end, specifies the domain part of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the service discovery DNS query."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"サービス検索がバックエンドで使用されていると、サービス検索 DNS クエリーのドメ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: Use the domain part of machine's hostname"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: マシンのホスト名のドメイン部分を使用します"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "override_gid (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "override_gid (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Override the primary GID value with the one specified."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "プライマリー GID の値を指定されたもので上書きします。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "case_sensitive (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Case sensitive. This value is invalid for AD provider."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Case insensitive."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Preserving"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Same as False (case insensitive), but does not lowercase names in the result "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"of NSS operations. Note that name aliases (and in case of services also "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"protocol names) are still lowercased in the output."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Treat user and group names as case sensitive. At the moment, this option is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"not supported in the local provider. Possible option values are: "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: True (False for AD provider)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "subdomain_inherit (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Specifies a list of configuration parameters that should be inherited by a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"subdomain. Please note that only selected parameters can be inherited. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Currently the following options can be inherited:"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ignore_group_members"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_purge_cache_timeout"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:2735 sssd-ldap.5.xml:1111
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_use_tokengroups"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_principal"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"is not set explicitly)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"subdomain_inherit = ldap_purge_cache_timeout\n"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:2745 sssd-secrets.5.xml:448
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Note: This option only works with the IPA and AD provider."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "subdomain_homedir (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "subdomain_homedir (文字列)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgid "flat (NetBIOS) name of a subdomain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "サブドメインのフラット (NetBIOS) 名。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Use this homedir as default value for all subdomains within this domain in "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"IPA AD trust. See <emphasis>override_homedir</emphasis> for info about "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"possible values. In addition to those, the expansion below can only be used "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"with <emphasis>subdomain_homedir</emphasis>. <placeholder type="
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"\"variablelist\" id=\"0\"/>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The value can be overridden by <emphasis>override_homedir</emphasis> option."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"値は <emphasis>override_homedir</emphasis> オプションにより上書きできます。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: <filename>/home/%d/%u</filename>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: <filename>/home/%d/%u</filename>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "realmd_tags (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "realmd_tags (文字列)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Various tags stored by the realmd configuration service for this domain."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "cached_auth_timeout (int)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies time in seconds since last successful online authentication for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"which user will be authenticated using cached credentials while SSSD is in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the online mode."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Special value 0 implies that this feature is disabled."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please note that if <quote>cached_auth_timeout</quote> is longer than "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>pam_id_timeout</quote> then the back end could be called to handle "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>initgroups.</quote>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"These configuration options can be present in a domain configuration "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"section, that is, in a section called <quote>[domain/<replaceable>NAME</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"これらの設定オプションはドメイン設定のセクション、つまり <quote>[domain/"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>NAME</replaceable>]</quote> に存在します <placeholder type="
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\"variablelist\" id=\"0\"/>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "proxy_pam_target (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "proxy_pam_target (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The proxy target PAM proxies to."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "中継するプロキシターゲット PAM です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Default: not set by default, you have to take an existing pam configuration "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"or create a new one and add the service name here."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"初期値: 設定されません。既存の PAM 設定を使用するか、新しく作成してサービス名"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"をここに追加する必要があります。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "proxy_lib_name (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "proxy_lib_name (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The name of the NSS library to use in proxy domains. The NSS functions "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"searched for in the library are in the form of _nss_$(libName)_$(function), "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for example _nss_files_getpwent."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"プロキシードメインにおいて使用する NSS ライブラリーの名前です。ライブラリーに"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"おいて検索する NSS 関数は _nss_$(libName)_$(function) の形式です。たとえば "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"_nss_files_getpwent です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "proxy_fast_alias (boolean)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "proxy_fast_alias (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When a user or group is looked up by name in the proxy provider, a second "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"lookup by ID is performed to \"canonicalize\" the name in case the requested "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"name was an alias. Setting this option to true would cause the SSSD to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"perform the ID lookup from cache for performance reasons."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "proxy_max_children (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"This option specifies the number of pre-forked proxy children. It is useful "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for high-load SSSD environments where sssd may run out of available child "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"slots, which would cause some issues due to the requests being queued."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Options valid for proxy domains. <placeholder type=\"variablelist\" id="
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"プロキシドメインに対して有効なオプションです。 <placeholder type="
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\"variablelist\" id=\"0\"/>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Application domains"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"SSSD, with its D-Bus interface (see <citerefentry> <refentrytitle>sssd-ifp</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>) is appealing to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"applications as a gateway to an LDAP directory where users and groups are "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"stored. However, contrary to the traditional SSSD deployment where all users "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"and groups either have POSIX attributes or those attributes can be inferred "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"from the Windows SIDs, in many cases the users and groups in the application "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"support scenario have no POSIX attributes. Instead of setting a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>[domain/<replaceable>NAME</replaceable>]</quote> section, the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"administrator can set up an <quote>[application/<replaceable>NAME</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable>]</quote> section that internally represents a domain with type "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>application</quote> optionally inherits settings from a tradition "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"SSSD domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that the application domain must still be explicitly enabled in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the <quote>domains</quote> parameter so that the lookup order between the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"application domain and its POSIX sibling domain is set correctly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Application domain parameters"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "inherit_from (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The SSSD POSIX-type domain the application domain inherits all settings "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"from. The application domain can moreover add its own settings to the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"application settings that augment or override the <quote>sibling</quote> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domain settings."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The following example illustrates the use of an application domain. In this "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"setup, the POSIX domain is connected to an LDAP server and is used by the OS "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"through the NSS responder. In addition, the application domain also requests "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the telephoneNumber attribute, stores it as the phone attribute in the cache "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"and makes the phone attribute reachable through the D-Bus interface."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains = appdom, posixdom\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"user_attributes = +phone\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"id_provider = ldap\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ldap_uri = ldap://ldap.example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_search_base = dc=example,dc=com\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"inherit_from = posixdom\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ldap_user_extra_attrs = phone:telephoneNumber\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The local domain section"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ローカルドメインのセクション"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This section contains settings for domain that stores users and groups in "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"SSSD native database, that is, a domain that uses "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>id_provider=local</replaceable>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"このセクションは、ユーザーとグループを SSSD ネイティブデータベースに保存する"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ドメイン、つまり、 <replaceable>id_provider=local</replaceable> を使用するド"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"メインに対する設定を含みます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "default_shell (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "default_shell (文字列)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The default shell for users created with SSSD userspace tools."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SSSD ユーザー空間ツールを用いて作成されたユーザーの初期シェルです。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: <filename>/bin/bash</filename>"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "初期値: <filename>/bin/bash</filename>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "base_directory (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "base_directory (文字列)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"The tools append the login name to <replaceable>base_directory</replaceable> "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"and use that as the home directory."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"ツールがログイン名を <replaceable>base_directory</replaceable> に追加して、"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ホームディレクトリーとして使用します。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: <filename>/home</filename>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "初期値: <filename>/home</filename>"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "create_homedir (bool)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "create_homedir (論理値)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Indicate if a home directory should be created by default for new users. "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Can be overridden on command line."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"初期状態で新規ユーザーに対するホームディレクトリーが作成されるかを指示しま"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"す。コマンドラインにおいて上書きできます。"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd.conf.5.xml:3004 sssd.conf.5.xml:3016
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: TRUE"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "初期値: TRUE"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "remove_homedir (bool)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "remove_homedir (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Indicate if a home directory should be removed by default for deleted "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"users. Can be overridden on command line."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"初期状態で新規ユーザーに対するホームディレクトリーが削除されるかを指示しま"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"す。コマンドラインにおいて上書きできます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "homedir_umask (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "homedir_umask (整数)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Used by <citerefentry> <refentrytitle>sss_useradd</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>8</manvolnum> </citerefentry> to specify the default permissions "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"on a newly created home directory."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"新規に作成されるホームディレクトリーにパーミッションの初期値を指定するために "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sss_useradd</refentrytitle> <manvolnum>8</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry> により使用されます。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: 077"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 077"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "skel_dir (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "skel_dir (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The skeleton directory, which contains files and directories to be copied in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"the user's home directory, when the home directory is created by "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sss_useradd</refentrytitle> <manvolnum>8</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ホームディレクトリーが <citerefentry> <refentrytitle>sss_useradd</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> により作成されると"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"き、ユーザーのホームディレクトリーにコピーされるファイルおよびディレクトリー"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"を含む、スケルトンディレクトリーです。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: <filename>/etc/skel</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: <filename>/etc/skel</filename>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "mail_dir (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "mail_dir (文字列)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The mail spool directory. This is needed to manipulate the mailbox when its "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"corresponding user account is modified or deleted. If not specified, a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"default value is used."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"メールスプールディレクトリーです。これに対応するユーザーアカウントが変更また"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"は削除されたとき、これを操作する必要があります。指定されていなければ、初期値"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: <filename>/var/mail</filename>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "初期値: <filename>/var/mail</filename>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "userdel_cmd (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "userdel_cmd (文字列)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The command that is run after a user is removed. The command us passed the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"username of the user being removed as the first and only parameter. The "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"return code of the command is not taken into account."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ユーザーの削除後に実行されるコマンドです。コマンドは最初の唯一のパラメーター"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"として削除されるユーザーのユーザー名を渡します。コマンドの返り値は考慮されま"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: None, no command is run"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "初期値: なし、コマンドを実行しません"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "TRUSTED DOMAIN SECTION"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Some options used in the domain section can also be used in the trusted "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain section, that is, in a section called <quote>[domain/"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<replaceable>DOMAIN_NAME</replaceable>/<replaceable>TRUSTED_DOMAIN_NAME</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable>]</quote>. Where DOMAIN_NAME is the actual joined-to base "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain. Please refer to examples below for explanation. Currently supported "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"options in the trusted domain section are:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_search_base,"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_search_base,"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_group_search_base,"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_netgroup_search_base,"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_service_search_base,"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_server,"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_backup_server,"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ad_site,"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "use_fully_qualified_names"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For more details about these options see their individual description in the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "EXAMPLES"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains = LDAP\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"services = nss, pam\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"config_file_version = 2\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"filter_groups = root\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"filter_users = root\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"id_provider = ldap\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_uri = ldap://ldap.example.com\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_search_base = dc=example,dc=com\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"auth_provider = krb5\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"krb5_server = kerberos.example.com\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"krb5_realm = EXAMPLE.COM\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"min_id = 10000\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"max_id = 20000\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"enumerate = False\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains = LDAP\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"services = nss, pam\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"config_file_version = 2\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"filter_groups = root\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"filter_users = root\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ldap\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"ldap_uri = ldap://ldap.example.com\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"ldap_search_base = dc=example,dc=com\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"auth_provider = krb5\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"krb5_realm = EXAMPLE.COM\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"min_id = 10000\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"max_id = 20000\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"enumerate = False\n"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher#| "The following example shows a typical SSSD config. It does not describe "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#| "configuration of the domains themselves - refer to documentation on "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#| "configuring domains for more details. <placeholder type=\"programlisting"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#| "\" id=\"0\"/>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"1. The following example shows a typical SSSD config. It does not describe "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"configuration of the domains themselves - refer to documentation on "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"configuring domains for more details. <placeholder type=\"programlisting\" "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"以下の例は SSSD の一般的な設定を示します。ドメイン自身の設定を説明していませ"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ん - ドメインの設定に関する詳細はドキュメントを参照してください。 "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"use_fully_qualified_names = false\n"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"2. The following example shows configuration of IPA AD trust where the AD "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"forest consists of two domains in a parent-child structure. Suppose IPA "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"domain (ipa.com) has trust with AD domain(ad.com). ad.com has child domain "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"(child.ad.com). To enable shortnames in the child domain the following "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"configuration should be used. <placeholder type=\"programlisting\" id=\"0\"/"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-ldap"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "sssd-ldap"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SSSD LDAP provider"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of LDAP domains for "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"</citerefentry>. Refer to the <quote>FILE FORMAT</quote> section of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum> </citerefentry> manual page for detailed syntax information."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"このマニュアルページは <citerefentry> <refentrytitle>sssd</refentrytitle> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> 向けの LDAP ドメインの設定を説明して"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"います。詳細な構文については <citerefentry> <refentrytitle>sssd.conf</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> マニュアルページの "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ファイル形式</quote> セクションを参照してください。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "You can configure SSSD to use more than one LDAP domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SSSD が複数の LDAP ドメインを使用するよう設定できます。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"LDAP back end supports id, auth, access and chpass providers. If you want to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"authenticate against an LDAP server either TLS/SSL or LDAPS is required. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<command>sssd</command> <emphasis>does not</emphasis> support authentication "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"over an unencrypted channel. If the LDAP server is used only as an identity "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"provider, an encrypted channel is not needed. Please refer to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<quote>ldap_access_filter</quote> config option for more information about "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"using LDAP as an access provider."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"LDAP バックエンドは id, auth, access および chpass プロバイダーをサポートしま"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"す。 LDAP サーバーに対して認証したければ、 TLS/SSL または LDAPS のどちらかが"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"必要になります。 <command>sssd</command> は暗号化されないチャネルにおける認証"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"はサポート<emphasis>されません</emphasis>。 LDAP サーバーが識別プロバイダーと"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"してのみ使用されるならば、暗号化チャネルは必要ありません。アクセスプロバイ"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ダーとして LDAP を使用することの詳細は <quote>ldap_access_filter</quote> 設定"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"オプションを参照してください。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:49 sssd-simple.5.xml:69 sssd-ipa.5.xml:75 sssd-ad.5.xml:99
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd-krb5.5.xml:63 sssd-ifp.5.xml:44 sssd-files.5.xml:57
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sssd-secrets.5.xml:120 sssd-session-recording.5.xml:58 sssd-kcm.8.xml:139
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "CONFIGURATION OPTIONS"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "設定オプション"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_uri, ldap_backup_uri (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_uri, ldap_backup_uri (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"should connect in the order of preference. Refer to the <quote>FAILOVER</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> section for more information on failover and server redundancy. If "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"neither option is specified, service discovery is enabled. For more "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"information, refer to the <quote>SERVICE DISCOVERY</quote> section."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The format of the URI must match the format defined in RFC 2732:"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "URI の形式は RFC 2732 に決められている形式と一致しなければいけません:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap[s]://<host>[:port]"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap[s]://<host>[:port]"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"For explicit IPv6 addresses, <host> must be enclosed in brackets []"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"IPv6 アドレスを明示するために、<host> を角括弧 [] でくくる必要がありま"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "example: ldap://[fc00::126:25]:389"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "例: ldap://[fc00::126:25]:389"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_chpass_uri, ldap_chpass_backup_uri (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"should connect in the order of preference to change the password of a user. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Refer to the <quote>FAILOVER</quote> section for more information on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"failover and server redundancy."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "To enable service discovery ldap_chpass_dns_service_name must be set."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"サービス discovery ldap_chpass_dns_service_name を有効にするには、設定する必"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: empty, i.e. ldap_uri is used."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "初期値: 空、つまり ldap_uri が使用されます。"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "ldap_search_base (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "ldap_search_base (文字列)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "The default base DN to use for performing LDAP user operations."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "LDAP ユーザー操作を実行するために使用される初期ベース DN です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Starting with SSSD 1.7.0, SSSD supports multiple search bases using the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"SSSD 1.7.0 以降、SSSD は次の構文を使用して複数の検索ベースをサポートします:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "範囲は \"base\", \"onelevel\" または \"subtree\" のどれかです。"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd-ldap.5.xml:122 include/ldap_search_bases.xml:18
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"The filter must be a valid LDAP search filter as specified by http://www."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"フィルターは http://www.ietf.org/rfc/rfc2254.txt により指定されたような有効"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"な LDAP 検索フィルターである必要があります。"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd-ldap.5.xml:126 sssd-ldap.5.xml:662 sssd-ad.5.xml:270
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sss_override.8.xml:137 sss_override.8.xml:234
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Examples:"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ldap_search_base = dc=example,dc=com (which is equivalent to) "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ldap_search_base = dc=example,dc=com?subtree?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ldap_search_base = dc=example,dc=com (which is equivalent to) "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap_search_base = dc=example,dc=com?subtree?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"(host=thishost)?dc=example.com?subtree?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"(host=thishost)?dc=example.com?subtree?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: It is unsupported to have multiple search bases which reference "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"identically-named objects (for example, groups with the same name in two "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"different search bases). This will lead to unpredictable behavior on client "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Default: If not set, the value of the defaultNamingContext or namingContexts "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"attribute from the RootDSE of the LDAP server is used. If "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"defaultNamingContext does not exist or has an empty value namingContexts is "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"used. The namingContexts attribute must have a single value with the DN of "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the search base of the LDAP server to make this work. Multiple values are "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"are not supported."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "ldap_schema (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_schema (文字列)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies the Schema Type in use on the target LDAP server. Depending on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the selected schema, the default attribute names retrieved from the servers "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"may vary. The way that some attributes are handled may also differ."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Four schema types are currently supported:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "rfc2307"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "rfc2307"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "rfc2307bis"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "rfc2307bis"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The main difference between these schema types is how group memberships are "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"recorded in the server. With rfc2307, group members are listed by name in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the <emphasis>memberUid</emphasis> attribute. With rfc2307bis and IPA, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"group members are listed by DN and stored in the <emphasis>member</emphasis> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"attribute. The AD schema type sets the attributes to correspond with Active "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Directory 2008r2 values."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Default: rfc2307"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "初期値: rfc2307"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_default_bind_dn (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_default_bind_dn (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The default bind DN to use for performing LDAP operations."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "LDAP ユーザー操作を実行するために使用される初期バインド DN です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_default_authtok_type (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_default_authtok_type (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "The type of the authentication token of the default bind DN."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "初期バインド DN の認証トークンの形式です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The two mechanisms currently supported are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "現在 2 つのメカニズムがサポートされます:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "password"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "password"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "obfuscated_password"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "obfuscated_password"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: password"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: password"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "ldap_default_authtok (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_default_authtok (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The authentication token of the default bind DN. Only clear text passwords "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"are currently supported."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"デフォルトのバインド DN の認証トークンです。平文テキストのパスワードのみが現"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_object_class (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_object_class (文字列)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a user entry in LDAP."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "LDAP にあるユーザーエントリーのオブジェクトクラスです。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: posixAccount"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: posixAccount"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_name (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_name (文字列)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's login name."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ユーザーのログイン名に対応する LDAP の属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_uid_number (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_user_uid_number (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's id."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ユーザーの ID に対応する LDAP の属性です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: uidNumber"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: uidNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gid_number (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_user_gid_number (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "The LDAP attribute that corresponds to the user's primary group id."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ユーザーのプライマリーグループ ID に対応する LDAP の属性です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: gidNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: gidNumber"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_primary_group (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Active Directory primary group attribute for ID-mapping. Note that this "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"attribute should only be set manually if you are running the <quote>ldap</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"quote> provider with ID mapping."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: unset (LDAP), primaryGroupID (AD)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gecos (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_gecos (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's gecos field."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ユーザーの gecos 項目に対応する LDAP の属性です。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: gecos"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: gecos"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_home_directory (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_user_home_directory (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that contains the name of the user's home directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ユーザーのホームディレクトリーの名前を含む LDAP の属性です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgid "Default: homeDirectory"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "初期値: homeDirectory"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_user_shell (string)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "ldap_user_shell (文字列)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "The LDAP attribute that contains the path to the user's default shell."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "ユーザーの初期シェルのパスを含む LDAP の属性です。"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Default: loginShell"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "初期値: loginShell"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "ldap_user_uuid (string)"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Default: not set in the general case, objectGUID for AD and ipaUniqueID for "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_objectsid (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_user_objectsid (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the objectSID of an LDAP user object. This "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"is usually only necessary for ActiveDirectory servers."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"LDAP ユーザーオブジェクトの objectSID を含む LDAP 属性です。これは通常 "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ActiveDirectory サーバーに対してのみ必要です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: objectSid for ActiveDirectory, not set for other servers."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_modify_timestamp (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_user_modify_timestamp (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:389 sssd-ldap.5.xml:971 sssd-ldap.5.xml:1194
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The LDAP attribute that contains timestamp of the last modification of the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"parent object."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "親オブジェクトの最終変更のタイムスタンプを含む LDAP 属性です。"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:393 sssd-ldap.5.xml:975 sssd-ldap.5.xml:1201
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Default: modifyTimestamp"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "初期値: modifyTimestamp"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "ldap_user_shadow_last_change (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "ldap_user_shadow_last_change (文字列)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (date of "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the last password change)."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> の対応部分(最終パスワード変更日)に対応する LDAP 属性の名前を"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: shadowLastChange"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: shadowLastChange"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_user_shadow_min (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "ldap_user_shadow_min (文字列)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (minimum "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"password age)."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"citerefentry> の対応部分(最小パスワード期限)に対応する LDAP 属性の名前を含"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: shadowMin"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "初期値: shadowMin"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_user_shadow_max (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "ldap_user_shadow_max (文字列)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (maximum "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"password age)."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"citerefentry> の対応部分(最大パスワード期限)に対応する LDAP 属性の名前を含"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowMax"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: shadowMax"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_warning (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_shadow_warning (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"(password warning period)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> の対応部分(パスワード警告期間)に対応する LDAP 属性の名前を含"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowWarning"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: shadowWarning"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_inactive (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_shadow_inactive (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(password inactivity period)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> の対応部分(パスワード無効期間)に対応する LDAP 属性の名前を含"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: shadowInactive"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: shadowInactive"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_user_shadow_expire (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_shadow_expire (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When using ldap_pwd_policy=shadow or ldap_account_expire_policy=shadow, this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameter contains the name of an LDAP attribute corresponding to its "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum> </citerefentry> counterpart (account expiration date)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_pwd_policy=shadow を使用するとき、このパラメーターは <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>shadow</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> の対応部分(アカウント失効日)に対応する LDAP 属性の名前を含み"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowExpire"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: shadowExpire"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_krb_last_pwd_change (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_krb_last_pwd_change (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"an LDAP attribute storing the date and time of last password change in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ldap_pwd_policy=mit_kerberos を使用しているとき、このパラメーターは Kerberos "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"の最終パスワード変更日時を保存する LDAP 属性の名前を含みます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: krbLastPwdChange"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: krbLastPwdChange"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_user_krb_password_expiration (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_krb_password_expiration (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"an LDAP attribute storing the date and time when current password expires."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_pwd_policy=mit_kerberos を使用しているとき、このパラメーターは現在のパス"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ワード失効日時を保存する LDAP 属性の名前を含みます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: krbPasswordExpiration"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: krbPasswordExpiration"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ad_account_expires (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_user_ad_account_expires (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of an LDAP attribute storing the expiration time of the account."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ldap_account_expire_policy=ad を使用するとき、このパラメーターはアカウントの"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"失効日時を保存する LDAP 属性の名前を含みます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: accountExpires"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: accountExpires"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ad_user_account_control (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_user_ad_user_account_control (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"of an LDAP attribute storing the user account control bit field."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_account_expire_policy=ad を使用するとき、このパラメーターはユーザーアカ"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ウントの制御ビット項目を保存する LDAP 属性の名前を含みます。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: userAccountControl"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: userAccountControl"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_ns_account_lock (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "ldap_ns_account_lock (文字列)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"When using ldap_account_expire_policy=rhds or equivalent, this parameter "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"determines if access is allowed or not."
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"ldap_account_expire_policy=rhds または同等のものを使用するとき、このパラメー"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"ターがアクセスが許可されるかされないかを決定します。"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "Default: nsAccountLock"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr "初期値: nsAccountLock"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "ldap_user_nds_login_disabled (string)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr "ldap_user_nds_login_disabled (文字列)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines if "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"access is allowed or not."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_account_expire_policy=nds を使用するとき、アクセスが許可されるかされない"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"かをこの属性が決定します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: loginDisabled"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: loginDisabled"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_user_nds_login_expiration_time (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "ldap_user_nds_login_expiration_time (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When using ldap_account_expire_policy=nds, this attribute determines until "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"which date access is granted."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_account_expire_policy=nds を使用しているとき、この属性はデータアクセスが"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"いつまで許可されるのかを決定します。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_user_nds_login_allowed_time_map (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "ldap_user_nds_login_allowed_time_map (文字列)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"When using ldap_account_expire_policy=nds, this attribute determines the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"hours of a day in a week when access is granted."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_account_expire_policy=nds を使用しているとき、この属性はアクセスが許可さ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"れるときの一週間の日の時間を決定します。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: loginAllowedTimeMap"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: loginAllowedTimeMap"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_principal (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_principal (文字列)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The LDAP attribute that contains the user's Kerberos User Principal Name "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ユーザーの Kerberos User Principal Name (UPN) を含む LDAP 属性です。"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: krbPrincipalName"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: krbPrincipalName"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_user_extra_attrs (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Comma-separated list of LDAP attributes that SSSD would fetch along with the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"usual set of user attributes."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The list can either contain LDAP attribute names only, or colon-separated "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"tuples of SSSD cache attribute name and LDAP attribute name. In case only "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute name is specified, the attribute is saved to the cache "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"verbatim. Using a custom SSSD attribute name might be required by "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"environments that configure several SSSD domains with different LDAP schemas."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please note that several attribute names are reserved by SSSD, notably the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>name</quote> attribute. SSSD would report an error if any of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"reserved attribute names is used as an extra attribute name."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_extra_attrs = telephoneNumber"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Save the <quote>telephoneNumber</quote> attribute from LDAP as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>telephoneNumber</quote> to the cache."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_extra_attrs = phone:telephoneNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Save the <quote>telephoneNumber</quote> attribute from LDAP as <quote>phone</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"quote> to the cache."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ssh_public_key (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_ssh_public_key (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "The LDAP attribute that contains the user's SSH public keys."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ユーザーの SSH 公開鍵を含む LDAP 属性です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: sshPublicKey"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_force_upper_case_realm (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_force_upper_case_realm (論理値)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Some directory servers, for example Active Directory, might deliver the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"realm part of the UPN in lower case, which might cause the authentication to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"fail. Set this option to a non-zero value if you want to use an upper-case "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"いくつかのディレクトリーサーバー、たとえば Active Directory、は小文字のレルム"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"を転送しません。それにより、認証が失敗します。もし大文字のレルムを使用したい"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"場合、このオプションを 0 以外に設定します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_enumeration_refresh_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_enumeration_refresh_timeout (整数)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies how many seconds SSSD has to wait before refreshing its cache of "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"enumerated records."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"SSSD が列挙レコードのキャッシュを更新する前に待つ必要がある秒数を指定します。"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_purge_cache_timeout (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "ldap_purge_cache_timeout (整数)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Determine how often to check the cache for inactive entries (such as groups "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"with no members and users who have never logged in) and remove them to save "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"使用していないエントリー(メンバーのいないグループやログインしたことがない"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ユーザーなど)に対してキャッシュを確認して、保存領域を節約するためにそれらを"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"削除する間隔を決めます。"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Setting this option to zero will disable the cache cleanup operation. Please "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"note that if enumeration is enabled, the cleanup task is required in order "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"to detect entries removed from the server and can't be disabled. By default, "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the cleanup task will run every 3 hours with enumeration enabled."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_fullname (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_user_fullname (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's full name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ユーザーの完全名に対応する LDAP 属性です。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd-ldap.5.xml:759 sssd-ldap.5.xml:1152 sssd-ldap.5.xml:1226
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: cn"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: cn"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_user_member_of (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_member_of (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that lists the user's group memberships."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ユーザーのグループメンバーを一覧にする LDAP 属性です。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: memberOf"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: memberOf"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_authorized_service (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap_user_authorized_service (文字列)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If access_provider=ldap and ldap_access_order=authorized_service, SSSD will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"use the presence of the authorizedService attribute in the user's LDAP entry "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to determine access privilege."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"もし access_provider=ldap かつ ldap_access_order=authorized_service ならば、"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD はアクセス権限を決定するために、ユーザーの LDAP エントリーにある "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"authorizedService 属性を使用します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"An explicit deny (!svc) is resolved first. Second, SSSD searches for "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"explicit allow (svc) and finally for allow_all (*)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"明示的な拒否 (!svc) が始めに解決されます。次に SSSD は明示的な許可 (svc) を検"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"索します。最後にすべて許可 (*) を検索します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"emphasis> include <quote>authorized_service</quote> in order for the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_user_authorized_service option to work."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: authorizedService"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: authorizedService"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_authorized_host (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_user_authorized_host (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"If access_provider=ldap and ldap_access_order=host, SSSD will use the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"presence of the host attribute in the user's LDAP entry to determine access "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access_provider=ldap かつ ldap_access_order=host ならば、 SSSD はアクセス権限"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"を決めるために、ユーザーの LDAP エントリーにあるホスト属性の存在を使用しま"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"An explicit deny (!host) is resolved first. Second, SSSD searches for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"explicit allow (host) and finally for allow_all (*)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"明示的な拒否 (!host) がまず解決されます。次に SSSD が明示的な許可 (host) を検"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"索します。最後にすべて許可 (*) が検索されます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that the ldap_access_order configuration option <emphasis>must</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"emphasis> include <quote>host</quote> in order for the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ldap_user_authorized_host option to work."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: host"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: host"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| msgid "ldap_user_authorized_host (string)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "ldap_user_authorized_rhost (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_user_authorized_host (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "If access_provider=ldap and ldap_access_order=host, SSSD will use the "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| "presence of the host attribute in the user's LDAP entry to determine "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#| "access privilege."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"If access_provider=ldap and ldap_access_order=rhost, SSSD will use the "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"presence of the rhost attribute in the user's LDAP entry to determine access "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"privilege. Similarly to host verification process."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"access_provider=ldap かつ ldap_access_order=host ならば、 SSSD はアクセス権限"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"を決めるために、ユーザーの LDAP エントリーにあるホスト属性の存在を使用しま"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "An explicit deny (!host) is resolved first. Second, SSSD searches for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "explicit allow (host) and finally for allow_all (*)."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"An explicit deny (!rhost) is resolved first. Second, SSSD searches for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"explicit allow (rhost) and finally for allow_all (*)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"明示的な拒否 (!host) がまず解決されます。次に SSSD が明示的な許可 (host) を検"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"索します。最後にすべて許可 (*) が検索されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please note that the ldap_access_order configuration option <emphasis>must</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"emphasis> include <quote>rhost</quote> in order for the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_user_authorized_rhost option to work."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "Default: host"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: rhost"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: host"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_certificate (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Name of the LDAP attribute containing the X509 certificate of the user."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "Default: filter"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: userCertificate;binary"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_user_email (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Name of the LDAP attribute containing the email address of the user."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: mail"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_group_object_class (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_group_object_class (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a group entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "LDAP にあるグループエントリーのオブジェクトクラスです。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: posixGroup"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: posixGroup"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_group_name (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_group_name (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the group name."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "グループ名に対応する LDAP 属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_group_gid_number (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_group_gid_number (文字列)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "The LDAP attribute that corresponds to the group's id."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "グループの ID に対応する LDAP 属性です。"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "ldap_group_member (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_group_member (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that contains the names of the group's members."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "グループのメンバーの名前を含む LDAP の属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: memberuid (rfc2307) / member (rfc2307bis)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: memberuid (rfc2307) / member (rfc2307bis)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_group_uuid (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ldap_group_objectsid (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "ldap_group_objectsid (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The LDAP attribute that contains the objectSID of an LDAP group object. This "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"is usually only necessary for ActiveDirectory servers."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"LDAP グループオブジェクトの objectSID を含む LDAP 属性です。これは通常 "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ActiveDirectory サーバーに対してのみ必要です。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_group_modify_timestamp (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "ldap_group_modify_timestamp (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_group_type (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains an integer value indicating the type of the "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"group and maybe other flags."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"This attribute is currently only used by the AD provider to determine if a "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"group is a domain local groups and has to be filtered out for trusted "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: groupType in the AD provider, otherwise not set"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_group_external_member (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The LDAP attribute that references group members that are defined in an "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"external domain. At the moment, only IPA's external members are supported."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: ipaExternalMember in the IPA provider, otherwise unset."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_group_nesting_level (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_group_nesting_level (整数)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"If ldap_schema is set to a schema format that supports nested groups (e.g. "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"RFC2307bis), then this option controls how many levels of nesting SSSD will "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"follow. This option has no effect on the RFC2307 schema."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_schema が入れ子グループ (例: RFC2307bis) をサポートするスキーマ形式に設"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"定されていると、このオプションが入れ子 SSSD がしたがうレベルを制御します。こ"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"のオプションは RFC2307 スキーマにおいて効果がありません。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Note: This option specifies the guaranteed level of nested groups to be "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"processed for any lookup. However, nested groups beyond this limit "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>may be</emphasis> returned if previous lookups already resolved "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the deeper nesting levels. Also, subsequent lookups for other groups may "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"enlarge the result set for original lookup if re-queried."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"If ldap_group_nesting_level is set to 0 then no nested groups are processed "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"at all. However, when connected to Active-Directory Server 2008 and later "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"using <quote>id_provider=ad</quote> it is furthermore required to disable "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"usage of Token-Groups by setting ldap_use_tokengroups to false in order to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"restrict group nesting."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: 2"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 2"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ldap_groups_use_matching_rule_in_chain"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_groups_use_matching_rule_in_chain"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option tells SSSD to take advantage of an Active Directory-specific "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"feature which may speed up group lookup operations on deployments with "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"complex or deep nested groups."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"In most common cases, it is best to leave this option disabled. It generally "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"only provides a performance increase on very complex nestings."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:1066 sssd-ldap.5.xml:1093
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"If this option is enabled, SSSD will use it if it detects that the server "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"supports it during initial connection. So \"True\" here essentially means "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"\"auto-detect\"."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:1072 sssd-ldap.5.xml:1099
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Note: This feature is currently known to work only with Active Directory "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"2008 R1 and later. See <ulink url=\"http://msdn.microsoft.com/en-us/library/"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"windows/desktop/aa746475%28v=vs.85%29.aspx\"> MSDN(TM) documentation</ulink> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"for more details."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_initgroups_use_matching_rule_in_chain"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_initgroups_use_matching_rule_in_chain"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"This option tells SSSD to take advantage of an Active Directory-specific "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"feature which might speed up initgroups operations (most notably when "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"dealing with complex or deep nested groups)."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This options enables or disables use of Token-Groups attribute when "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"performing initgroup for users from Active Directory Server 2008 and later."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: True for AD and IPA otherwise False."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_netgroup_object_class (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_netgroup_object_class (文字列)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "The object class of a netgroup entry in LDAP."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "LDAP にあるネットワークグループエントリーのオブジェクトクラスです。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "In IPA provider, ipa_netgroup_object_class should be used instead."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"IPA プロバイダーにおいては ipa_netgroup_object_class が代わりに使用されます。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: nisNetgroup"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "初期値: nisNetgroup"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_netgroup_name (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_netgroup_name (文字列)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "The LDAP attribute that corresponds to the netgroup name."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ネットワークグループ名に対応する LDAP 属性です。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "In IPA provider, ipa_netgroup_name should be used instead."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "IPA プロバイダーにおいては ipa_netgroup_name が代わりに使用されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_netgroup_member (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_netgroup_member (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "The LDAP attribute that contains the names of the netgroup's members."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ネットワークグループのメンバーの名前を含む LDAP 属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "In IPA provider, ipa_netgroup_member should be used instead."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"IPA プロバイダーにおいては ipa_netgroup_member が代わりに使用されます。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: memberNisNetgroup"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: memberNisNetgroup"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_netgroup_triple (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "ldap_netgroup_triple (文字列)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The LDAP attribute that contains the (host, user, domain) netgroup triples."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"ネットワークグループの三つ組(ホスト、ユーザー、ドメイン)を含む LDAP 属性で"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:1182 sssd-ldap.5.xml:1198
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "This option is not available in IPA provider."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "このオプションは IPA プロバイダーにおいて利用可能ではありません。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: nisNetgroupTriple"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: nisNetgroupTriple"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_netgroup_modify_timestamp (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_netgroup_modify_timestamp (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_object_class (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_service_object_class (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a service entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "LDAP にあるサービスエントリーのオブジェクトクラスです。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipService"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: ipService"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_name (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_service_name (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the name of service attributes and their "
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "サービス属性の名前とそのエイリアスを含む LDAP 属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_service_port (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_service_port (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that contains the port managed by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "このサービスにより管理されるポートを含む LDAP 属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipServicePort"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: ipServicePort"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_proto (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_service_proto (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the protocols understood by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "このサービスにより認識されるプロトコルを含む LDAP 属性です。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Default: ipServiceProtocol"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: ipServiceProtocol"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "ldap_service_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_service_search_base (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_search_timeout (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_search_timeout (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies the timeout (in seconds) that ldap searches are allowed to run "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"before they are cancelled and cached results are returned (and offline mode "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is entered)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note: this option is subject to change in future versions of the SSSD. It "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"will likely be replaced at some point by a series of timeouts for specific "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"lookup types."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"注: このオプションは SSSD の将来のバージョンにおいて変更される可能性がありま"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"す。特定の種類の検索のために一連のタイムアウトによりある時点に置き換えられる"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_enumeration_search_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_enumeration_search_timeout (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies the timeout (in seconds) that ldap searches for user and group "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"enumerations are allowed to run before they are cancelled and cached results "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"are returned (and offline mode is entered)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_network_timeout (integer)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_network_timeout (整数)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies the timeout (in seconds) after which the <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> following a <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> returns in case of no activity."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<citerefentry> <refentrytitle>connect</refentrytitle> <manvolnum>2</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"manvolnum> </citerefentry> に続けて <citerefentry> <refentrytitle>poll</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/<citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>select</refentrytitle> <manvolnum>2</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> が未使用を返した後のタイムアウト(秒単位)を指定します。"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_opt_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_opt_timeout (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies a timeout (in seconds) after which calls to synchronous LDAP APIs "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"will abort if no response is received. Also controls the timeout when "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"communicating with the KDC in case of SASL bind, the timeout of an LDAP bind "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"operation, password change extended operation and the StartTLS operation."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_connection_expire_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "ldap_connection_expire_timeout (整数)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies a timeout (in seconds) that a connection to an LDAP server will be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"maintained. After this time, the connection will be re-established. If used "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"in parallel with SASL/GSSAPI, the sooner of the two values (this value vs. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the TGT lifetime) will be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd-ldap.5.xml:1355 sssd-ldap.5.xml:2433
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 900 (15 minutes)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: 900 (15 分)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_page_size (integer)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ldap_page_size (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specify the number of records to retrieve from LDAP in a single request. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Some LDAP servers enforce a maximum limit per-request."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"1 回の要求で LDAP から取得するレコード数を指定します。いくつかの LDAP サー"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"バーは 1 要求あたりの最大数の制限を強制します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: 1000"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "初期値: 1000"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_disable_paging (boolean)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ldap_disable_paging (論理値)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Disable the LDAP paging control. This option should be used if the LDAP "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"server reports that it supports the LDAP paging control in its RootDSE but "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"it is not enabled or does not behave properly."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"LDAP ページング制御を無効にします。LDAP サーバーがその RootDSE において LDAP "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ページング制御をサポートするが、有効化されていない、もしくは正しく動作しない"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ことを報告する場合に、このオプションが使用されます。"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Example: OpenLDAP servers with the paging control module installed on the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"server but not enabled will report it in the RootDSE but be unable to use it."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"例: サーバーにページング制御モジュールがインストールされているが、RootDSE に"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"おいて有効化されていないと報告され、それを使用できない OpenLDAP サーバーで"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Example: 389 DS has a bug where it can only support a one paging control at "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"a time on a single connection. On busy clients, this can result in some "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"requests being denied."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"例: 389 DS は単一の接続において同時に 1 つのページ制御のみをサポートします。"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"負荷の高いクライアントにおいては、いくつかの要求が拒否される結果になる可能性"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_disable_range_retrieval (boolean)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ldap_disable_range_retrieval (論理値)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Disable Active Directory range retrieval."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "Active Directory の範囲の取得を無効化します。"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Active Directory limits the number of members to be retrieved in a single "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"lookup using the MaxValRange policy (which defaults to 1500 members). If a "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"group contains more members, the reply would include an AD-specific range "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"extension. This option disables parsing of the range extension, therefore "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"large groups will appear as having no members."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_sasl_minssf (integer)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ldap_sasl_minssf (整数)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"When communicating with an LDAP server using SASL, specify the minimum "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"security level necessary to establish the connection. The values of this "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"option are defined by OpenLDAP."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: Use the system default (usually specified by ldap.conf)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_deref_threshold (integer)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "ldap_deref_threshold (整数)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specify the number of group members that must be missing from the internal "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"cache in order to trigger a dereference lookup. If less members are missing, "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"they are looked up individually."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"You can turn off dereference lookups completely by setting the value to 0."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"A dereference lookup is a means of fetching all group members in a single "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"LDAP call. Different LDAP servers may implement different dereference "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"methods. The currently supported servers are 389/RHDS, OpenLDAP and Active "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<emphasis>Note:</emphasis> If any of the search bases specifies a search "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"filter, then the dereference lookup performance enhancement will be disabled "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"regardless of this setting."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_tls_reqcert (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_tls_reqcert (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies what checks to perform on server certificates in a TLS session, if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"any. It can be specified as one of the following values:"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"もしあれば、 TLS セッションにおいてサーバー証明書において実行するためにチェッ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"クするものを指定します。以下の値のうち 1 つを指定できます:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>never</emphasis> = The client will not request or check any server "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>never</emphasis> = クライアントがすべてのサーバー証明書を要求または"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>allow</emphasis> = The server certificate is requested. If no "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"certificate is provided, the session proceeds normally. If a bad certificate "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is provided, it will be ignored and the session proceeds normally."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>allow</emphasis> = サーバー証明書が要求されます。証明書が提供されな"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ければ、セッションが通常通り進められます。不正な証明書が提供されると、それは"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"無視され、セッションが通常通り進められます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>try</emphasis> = The server certificate is requested. If no "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"certificate is provided, the session proceeds normally. If a bad certificate "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is provided, the session is immediately terminated."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>try</emphasis> = サーバー証明書が要求されます。証明書が提供されなけ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"れば、セッションが通常通り進められます。不正な証明書が提供されると、セッショ"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>demand</emphasis> = The server certificate is requested. If no "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"certificate is provided, or a bad certificate is provided, the session is "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"immediately terminated."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>demand</emphasis> = サーバー証明書が要求されます。証明書が提供され"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"なければ、もしくは不正な証明書が提供されれば、セッションが直ちに終了します。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "<emphasis>hard</emphasis> = <quote>demand</quote> と同じです"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: hard"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: hard"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_tls_cacert (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_tls_cacert (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies the file that contains certificates for all of the Certificate "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Authorities that <command>sssd</command> will recognize."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies the file that contains certificates for all of the Certificate "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Authorities that <command>sssd</command> が認識するすべての認証局に対する証明"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"書を含むファイルを指定します。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1523 sssd-ldap.5.xml:1541 sssd-ldap.5.xml:1582
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: use OpenLDAP defaults, typically in <filename>/etc/openldap/ldap."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"conf</filename>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"初期値: OpenLDAP の初期値の使用、一般的に <filename>/etc/openldap/ldap.conf</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"filename> にあります"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_cacertdir (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_tls_cacertdir (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies the path of a directory that contains Certificate Authority "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"certificates in separate individual files. Typically the file names need to "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"be the hash of the certificate followed by '.0'. If available, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>cacertdir_rehash</command> can be used to create the correct names."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"個別のファイルに CA 証明書を含むディレクトリーのパスを指定します。一般的に"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"ファイル名は '.0' で終わる証明書のハッシュである必要があります。利用可能なら"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ば、<command>cacertdir_rehash</command> は正しい名前を作成するために使用でき"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_tls_cert (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_tls_cert (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the file that contains the certificate for the client's key."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "クライアントのキーに対する証明書を含むファイルを指定します。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_tls_key (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap_tls_key (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Specifies the file that contains the client's key."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "クライアントのキーを含むファイルを指定します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_tls_cipher_suite (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_tls_cipher_suite (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies acceptable cipher suites. Typically this is a colon separated "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum></citerefentry> for format."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_id_use_start_tls (boolean)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "ldap_id_use_start_tls (論理値)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Specifies that the id_provider connection must also use <systemitem class="
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"\"protocol\">tls</systemitem> to protect the channel."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"チャネルを保護するために <systemitem class=\"protocol\">tls</systemitem> も使"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"用する必要がある id_provider 接続を指定します。"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_id_mapping (boolean)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "ldap_id_mapping (論理値)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"Specifies that SSSD should attempt to map user and group IDs from the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap_user_objectsid and ldap_group_objectsid attributes instead of relying "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"on ldap_user_uid_number and ldap_group_gid_number."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Currently this feature supports only ActiveDirectory objectSID mapping."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"この機能は現在 ActiveDirectory objectSID マッピングのみサポートします。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_min_id, ldap_max_id (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"In contrast to the SID based ID mapping which is used if ldap_id_mapping is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"set to true the allowed ID range for ldap_user_uid_number and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_group_gid_number is unbound. In a setup with sub/trusted-domains this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"might lead to ID collisions. To avoid collisions ldap_min_id and ldap_max_id "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"can be set to restrict the allowed range for the IDs which are read directly "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"from the server. Sub-domains can then pick other ranges to map IDs."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set (both options are set to 0)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_sasl_mech (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "ldap_sasl_mech (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specify the SASL mechanism to use. Currently only GSSAPI is tested and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"使用する SASL メカニズムを指定します。現在 GSSAPI のみがテストされサポートさ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_sasl_authid (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "ldap_sasl_authid (文字列)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Specify the SASL authorization id to use. When GSSAPI is used, this "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"represents the Kerberos principal used for authentication to the directory. "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"This option can either contain the full principal (for example host/"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"myhost@EXAMPLE.COM) or just the principal name (for example host/myhost)."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: host/hostname@REALM"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "初期値: host/hostname@REALM"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_sasl_realm (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "ldap_sasl_realm (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Specify the SASL realm to use. When not specified, this option defaults to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"the value of krb5_realm. If the ldap_sasl_authid contains the realm as "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"well, this option is ignored."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: the value of krb5_realm."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: krb5_realm の値"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_sasl_canonicalize (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_sasl_canonicalize (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If set to true, the LDAP library would perform a reverse lookup to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"canonicalize the host name during a SASL bind."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"真に設定されていると、 LDAP ライブラリーは SASL バインド中にホスト名を正規化"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"するために逆引きを実行します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: false;"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: false;"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_krb5_keytab (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_krb5_keytab (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specify the keytab to use when using SASL/GSSAPI."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "SASL/GSSAPI を使用するときに使用するキーテーブルを指定します。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"初期値: システムのキーテーブル、通常 <filename>/etc/krb5.keytab</filename>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_krb5_init_creds (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_krb5_init_creds (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Specifies that the id_provider should init Kerberos credentials (TGT). This "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"action is performed only if SASL is used and the mechanism selected is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Kerberos クレディンシャル (TGT) を初期化する id_provider を指定します。この操"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"作は、 SASL が使用され、選択されたメカニズムが GSSAPI である場合のみ実行され"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_krb5_ticket_lifetime (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr "ldap_krb5_ticket_lifetime (整数)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the lifetime in seconds of the TGT if GSSAPI is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "GSSAPI が使用されている場合、TGT の有効期間を秒単位で指定します。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 86400 (24 hours)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 86400 (24 時間)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "krb5_server, krb5_backup_server (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "krb5_server, krb5_backup_server (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies the comma-separated list of IP addresses or hostnames of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Kerberos servers to which SSSD should connect in the order of preference. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For more information on failover and server redundancy, see the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>FAILOVER</quote> section. An optional port number (preceded by a "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"colon) may be appended to the addresses or hostnames. If empty, service "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"discovery is enabled - for more information, refer to the <quote>SERVICE "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"DISCOVERY</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When using service discovery for KDC or kpasswd servers, SSSD first searches "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for DNS entries that specify _udp as the protocol and falls back to _tcp if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"none are found."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"KDC または kpasswd サーバーに対してサービス検索を使用するとき、SSSD はまずプ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ロトコルとして _udp を指定する DNS エントリーを検索して、何も見つからなけれ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ば _tcp にフォールバックします。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option was named <quote>krb5_kdcip</quote> in earlier releases of SSSD. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"While the legacy name is recognized for the time being, users are advised to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"migrate their config files to use <quote>krb5_server</quote> instead."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"このオプションは以前の SSSD において <quote>krb5_kdcip</quote> という名前でし"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"た。古い名前がしばらく認められる間、ユーザーは代わりに <quote>krb5_server</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"quote> を使用するよう設定ファイルを移行することが推奨されます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1770 sssd-ipa.5.xml:432 sssd-krb5.5.xml:103
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_realm (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "krb5_realm (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specify the Kerberos REALM (for SASL/GSSAPI auth)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "(SASL/GSSAPI 認証向け) Kerberos レルムを指定します。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "初期値: システムの初期値、<filename>/etc/krb5.conf</filename> 参照。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "krb5_canonicalize (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "krb5_canonicalize (論理値)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies if the host principal should be canonicalized when connecting to "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"LDAP server. This feature is available with MIT Kerberos >= 1.7"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"LDAP サーバーに接続するとき、ホストのプリンシパルが正規化されるかどうかを指定"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"します。この機能は MIT Kerberos >= 1.7 で利用可能です。"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "krb5_use_kdcinfo (boolean)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "krb5_use_kdcinfo (論理値)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Specifies if the SSSD should instruct the Kerberos libraries what realm and "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"which KDCs to use. This option is on by default, if you disable it, you need "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"to configure the Kerberos library using the <citerefentry> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> </"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"citerefentry> configuration file."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"See the <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> manual page for more "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"information on the locator plugin."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"位置情報プラグインの詳細は <citerefentry> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle> <manvolnum>8</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"manvolnum> </citerefentry> マニュアルページを参照ください。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_pwd_policy (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_pwd_policy (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Select the policy to evaluate the password expiration on the client side. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The following values are allowed:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"クライアント側においてパスワード期限切れを評価するためのポリシーを選択しま"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"す。以下の値が許容されます:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>none</emphasis> - No evaluation on the client side. This option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"cannot disable server-side password policies."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>none</emphasis> - クライアント側において評価しません。このオプショ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ンはサーバー側のパスワードポリシーを無効にできません。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>shadow</emphasis> - Use <citerefentry><refentrytitle>shadow</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum></citerefentry> style attributes to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"evaluate if the password has expired."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>shadow</emphasis> - パスワードが失効したかを評価するために "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry><refentrytitle>shadow</refentrytitle> <manvolnum>5</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"manvolnum></citerefentry> 形式の属性を使用します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>mit_kerberos</emphasis> - Use the attributes used by MIT Kerberos "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to determine if the password has expired. Use chpass_provider=krb5 to update "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"these attributes when the password is changed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>mit_kerberos</emphasis> - パスワードが期限切れしているかを決定する"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ために MIT Kerberos により使用される属性を使用します。パスワードが変更される"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"とき、これらの属性を更新するために chpass_provider=krb5 を使用します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>Note</emphasis>: if a password policy is configured on server "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"side, it always takes precedence over policy set with this option."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_referrals (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_referrals (論理値)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Specifies whether automatic referral chasing should be enabled."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "自動参照追跡が有効化されるかを指定します。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that sssd only supports referral chasing when it is compiled "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"with OpenLDAP version 2.4.13 or higher."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"OpenLDAP バージョン 2.4.13 およびそれ以降とともにコンパイルされているとき、 "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"sssd のみが参照追跡をサポートすることに注意してください。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Chasing referrals may incur a performance penalty in environments that use "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"them heavily, a notable example is Microsoft Active Directory. If your setup "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"does not in fact require the use of referrals, setting this option to false "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"might bring a noticeable performance improvement."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_dns_service_name (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap_dns_service_name (文字列)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the service name to use when service discovery is enabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"サービス検索が有効にされているときに使用するサービスの名前を指定します。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: ldap"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: ldap"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_chpass_dns_service_name (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_chpass_dns_service_name (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the service name to use to find an LDAP server which allows "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"password changes when service discovery is enabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"サービス検索が有効にされているときに、パスワード変更を許可する LDAP サーバー"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"を検索するために使用するサービスの名前を指定します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set, i.e. service discovery is disabled"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 設定されていません、つまりサービス検索が無効にされています"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_chpass_update_last_change (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_chpass_update_last_change (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies whether to update the ldap_user_shadow_last_change attribute with "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"days since the Epoch after a password change operation."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_access_filter (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_access_filter (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If using access_provider = ldap and ldap_access_order = filter (default), "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this option is mandatory. It specifies an LDAP search filter criteria that "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"must be met for the user to be granted access on this host. If "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access_provider = ldap, ldap_access_order = filter and this option is not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"set, it will result in all users being denied access. Use access_provider = "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"permit to change this default behavior. Please note that this filter is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"applied on the LDAP user entry only and thus filtering based on nested "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"groups may not work (e.g. memberOf attribute on AD entries points only to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"direct parents). If filtering based on nested groups is required, please see "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd-simple</refentrytitle><manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access_provider = ldap\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_access_filter = (employeeType=admin)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This example means that access to this host is restricted to users whose "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"employeeType attribute is set to \"admin\"."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Offline caching for this feature is limited to determining whether the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"user's last online login was granted access permission. If they were granted "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access during their last login, they will continue to be granted access "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"while offline and vice versa."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:1972 sssd-ldap.5.xml:2029
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Empty"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 空白"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_account_expire_policy (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_account_expire_policy (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"With this option a client side evaluation of access control attributes can "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"このオプションを使用すると、アクセス制御属性のクライアント側評価が有効になり"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that it is always recommended to use server side access control, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"i.e. the LDAP server should deny the bind request with a suitable error code "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"even if the password is correct."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"必ずサーバー側のアクセス制御を使用することが推奨されることに注意してくださ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"い。つまり、パスワードが正しいときさえ、適切なエラーコードでバインド要求を拒"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "The following values are allowed:"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "以下の値が許可されます:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"determine if the account is expired."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>shadow</emphasis>: アカウントが失効しているかを決めるために "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_user_shadow_expire の値を使用します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>ad</emphasis>: use the value of the 32bit field "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_user_ad_user_account_control and allow access if the second bit is not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"set. If the attribute is missing access is granted. Also the expiration time "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"of the account is checked."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, <emphasis>389ds</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"emphasis>: use the value of ldap_ns_account_lock to check if access is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"allowed or not."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, <emphasis>389ds</"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"emphasis>: アクセスが許可されるかされないかを確認するために "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_ns_account_lock の値を使用します。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<emphasis>nds</emphasis>: the values of "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_user_nds_login_expiration_time are used to check if access is allowed. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If both attributes are missing access is granted."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>nds</emphasis>: アクセスが許可されるかを確認するために the values "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled および "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_user_nds_login_expiration_time の値が使用されます。どの値もなければ、ア"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that the ldap_access_order configuration option <emphasis>must</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"emphasis> include <quote>expire</quote> in order for the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_account_expire_policy option to work."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_access_order (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_access_order (文字列)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Comma separated list of access control options. Allowed values are:"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"アクセス制御オプションのカンマ区切り一覧です。許可される値は次のとおりです:"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<emphasis>filter</emphasis>: use ldap_access_filter"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr "<emphasis>filter</emphasis>: ldap_access_filter を使用します"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>lockout</emphasis>: use account locking. If set, this option "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"and has value of '000001010000Z'. Please see the option ldap_pwdlockout_dn. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that 'access_provider = ldap' must be set for this feature to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis> Please note that this option is superseded by the <quote>ppolicy</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"quote> option and might be removed in a future release. </emphasis>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>ppolicy</emphasis>: use account locking. If set, this option "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"and has value of '000001010000Z' or represents any time in the past. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"value of the 'pwdAccountLockedTime' attribute must end with 'Z', which "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"denotes the UTC time zone. Other time zones are not currently supported and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"will result in \"access-denied\" when users attempt to log in. Please see "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"must be set for this feature to work."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "<emphasis>expire</emphasis>: ldap_account_expire_policy を使用します"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"pwd_expire_policy_renew: </emphasis> These options are useful if users are "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"interested in being warned that password is about to expire and "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"authentication is based on using a different method than passwords - for "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"example SSH keys."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The difference between these options is the action taken if user password is "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"expired: pwd_expire_policy_reject - user is denied to log in, "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"pwd_expire_policy_warn - user is still able to log in, "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"pwd_expire_policy_renew - user is prompted to change his password "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"immediately."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Note If user password is expired no explicit message is prompted by SSSD."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that 'access_provider = ldap' must be set for this feature to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"work. Also 'ldap_pwd_policy' must be set to an appropriate password policy."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>authorized_service</emphasis>: use the authorizedService attribute "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to determine access"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>authorized_service</emphasis>: アクセス権を決定するために "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"authorizedService 属性を使用します"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>host</emphasis>: use the host attribute to determine access"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<emphasis>host</emphasis>: アクセス権を決めるために host 属性を使用します"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| "<emphasis>host</emphasis>: use the host attribute to determine access"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>rhost</emphasis>: use the rhost attribute to determine whether "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"remote host can access"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>host</emphasis>: アクセス権を決めるために host 属性を使用します"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note, rhost field in pam is set by application, it is better to check "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"what the application sends to pam, before enabling this access control option"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: filter"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: filter"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that it is a configuration error if a value is used more than "
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "値が複数使用されていると設定エラーになることに注意してください。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_pwdlockout_dn (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"This option specifies the DN of password policy entry on LDAP server. Please "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"note that absence of this option in sssd.conf in case of enabled account "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"lockout checking will yield access denied as ppolicy attributes on LDAP "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"server cannot be checked properly."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: cn=ppolicy,ou=policies,$ldap_search_base"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_deref (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr "ldap_deref (文字列)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Specifies how alias dereferencing is done when performing a search. The "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"following options are allowed:"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"検索を実行するときにどのように参照解決を実行するかを指定します。以下のオプ"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ションが許容されます:"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<emphasis>never</emphasis>: Aliases are never dereferenced."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "<emphasis>never</emphasis>: エイリアスが参照解決されません。"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the base object, but not in locating the base object of the search."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>searching</emphasis>: エイリアスはベースオブジェクトの下位に参照解"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"決されますが、検索のベースオブジェクトの位置を探すときはされません。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>finding</emphasis>: Aliases are only dereferenced when locating "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the base object of the search."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<emphasis>finding</emphasis>: エイリアスは検索のベースオブジェクトの位置を探"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"すときのみ参照解決されます。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>always</emphasis>: Aliases are dereferenced both in searching and "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"in locating the base object of the search."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>always</emphasis>: エイリアスは検索のベースオブジェクトを検索すると"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"きも位置を検索するときも参照解決されます。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"client libraries)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"初期値: 空白(LDAP クライアントライブラリにより <emphasis>never</emphasis> と"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "ldap_rfc2307_fallback_to_local_users (boolean)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "ldap_rfc2307_fallback_to_local_users (論理値)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Allows to retain local users as members of an LDAP group for servers that "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"use the RFC2307 schema."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"In some environments where the RFC2307 schema is used, local users are made "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"members of LDAP groups by adding their names to the memberUid attribute. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The self-consistency of the domain is compromised when this is done, so SSSD "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"would normally remove the \"missing\" users from the cached group "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"memberships as soon as nsswitch tries to fetch information about the user "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"via getpw*() or initgroups() calls."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"This option falls back to checking if local users are referenced, and caches "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"them so that later initgroups() calls will augment the local users with the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"additional LDAP groups."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#| msgid "ldap_opt_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "wildcard_limit (integer)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "ldap_opt_timeout (整数)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Specifies an upper limit on the number of entries that are downloaded during "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"a wildcard lookup."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "At the moment, only the InfoPipe responder supports wildcard lookups."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: 1000 (often the size of one page)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"All of the common configuration options that apply to SSSD domains also "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"apply to LDAP domains. Refer to the <quote>DOMAIN SECTIONS</quote> section "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"manvolnum> </citerefentry> manual page for full details. <placeholder type="
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"\"variablelist\" id=\"0\"/>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"SSSD ドメインに適用するすべての全体設定オプションを LDAP ドメインに適用しま"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"す。完全な詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> マニュアルページの <quote>ドメインセ"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"クション</quote> を参照してください。 <placeholder type=\"variablelist\" id="
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "SUDO OPTIONS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "SUDO オプション"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The detailed instructions for configuration of sudo_provider are in the "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_sudorule_object_class (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudorule_object_class (文字列)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "The object class of a sudo rule entry in LDAP."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "LDAP にある sudo ルールエントリーのオブジェクトクラスです。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: sudoRole"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "初期値: sudoRole"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_sudorule_name (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudorule_name (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo rule name."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "sudo ルール名に対応する LDAP 属性です。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_sudorule_command (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "ldap_sudorule_command (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the command name."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "コマンド名に対応する LDAP 属性です。"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoCommand"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "初期値: sudoCommand"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_host (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "ldap_sudorule_host (文字列)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"The LDAP attribute that corresponds to the host name (or host IP address, "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"host IP network, or host netgroup)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"ホスト名(またはホスト IP アドレス、ホスト IP ネットワーク、ホストネットワー"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"クグループ)に対応する LDAP 属性です。"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoHost"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "初期値: sudoHost"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_user (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudorule_user (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The LDAP attribute that corresponds to the user name (or UID, group name or "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"user's netgroup)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ユーザー名(または UID、グループ名、ユーザーのネットワークグループ)に対応す"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: sudoUser"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: sudoUser"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_sudorule_option (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "ldap_sudorule_option (文字列)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo options."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "sudo オプションに対応する LDAP 属性です。"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: sudoOption"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "初期値: sudoOption"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_sudorule_runasuser (string)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "ldap_sudorule_runasuser (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The LDAP attribute that corresponds to the user name that commands may be "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "コマンドを実行するユーザー名に対応する LDAP 属性です。"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: sudoRunAsUser"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "初期値: sudoRunAsUser"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_sudorule_runasgroup (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_sudorule_runasgroup (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The LDAP attribute that corresponds to the group name or group GID that "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"commands may be run as."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"コマンドを実行するグループ名またはグループの GID に対応する LDAP 属性です。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: sudoRunAsGroup"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: sudoRunAsGroup"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ldap_sudorule_notbefore (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudorule_notbefore (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The LDAP attribute that corresponds to the start date/time for when the sudo "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"rule is valid."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "sudo ルールが有効になる開始日時に対応する LDAP 属性です。"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: sudoNotBefore"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: sudoNotBefore"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_sudorule_notafter (string)"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr "ldap_sudorule_notafter (文字列)"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The LDAP attribute that corresponds to the expiration date/time, after which "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"the sudo rule will no longer be valid."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"sudo ルールが有効ではなくなった後に、期限切れとなる日時に対応する LDAP 属性で"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: sudoNotAfter"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "初期値: sudoNotAfter"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_sudorule_order (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_sudorule_order (文字列)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The LDAP attribute that corresponds to the ordering index of the rule."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ルールの並び替えインデックスに対応する LDAP 属性です。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: sudoOrder"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "初期値: sudoOrder"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_sudo_full_refresh_interval (integer)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr "ldap_sudo_full_refresh_interval (整数)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"How many seconds SSSD will wait between executing a full refresh of sudo "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"rules (which downloads all rules that are stored on the server)."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval </"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"値は <emphasis>ldap_sudo_smart_refresh_interval</emphasis> より大きい必要があ"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: 21600 (6 hours)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 21600 (6 時間)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_sudo_smart_refresh_interval (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "ldap_sudo_smart_refresh_interval (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"How many seconds SSSD has to wait before executing a smart refresh of sudo "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"rules (which downloads all rules that have USN higher than the highest USN "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"of cached rules)."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"If USN attributes are not supported by the server, the modifyTimestamp "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"attribute is used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_sudo_use_host_filter (boolean)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudo_use_host_filter (論理値)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"If true, SSSD will download only rules that are applicable to this machine "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"(using the IPv4 or IPv6 host/network addresses and hostnames)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_sudo_hostnames (string)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr "ldap_sudo_hostnames (文字列)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Space separated list of hostnames or fully qualified domain names that "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"should be used to filter the rules."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ルールをフィルターするために使用されるホスト名または完全修飾ドメイン名の空白"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"If this option is empty, SSSD will try to discover the hostname and the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fully qualified domain name automatically."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ldap.5.xml:2466 sssd-ldap.5.xml:2489 sssd-ldap.5.xml:2507
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"If <emphasis>ldap_sudo_use_host_filter</emphasis> is <emphasis>false</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"emphasis> then this option has no effect."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>ldap_sudo_use_host_filter</emphasis> が <emphasis>false</emphasis> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ならば、このオプションは効果を持ちません。"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:2471 sssd-ldap.5.xml:2494
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: not specified"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "初期値: 指定なし"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudo_ip (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_sudo_ip (文字列)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Space separated list of IPv4 or IPv6 host/network addresses that should be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"used to filter the rules."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ルールをフィルターするために使用される、IPv4 または IPv6 ホスト/ネットワーク"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"アドレスの空白区切り一覧です。"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"If this option is empty, SSSD will try to discover the addresses "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"automatically."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"このオプションが空白ならば、SSSD は自動的にアドレスを検索しようとします。"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_sudo_include_netgroups (boolean)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_sudo_include_netgroups (論理値)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"If true then SSSD will download every rule that contains a netgroup in "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"sudoHost attribute."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_sudo_include_regexp (boolean)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_sudo_include_regexp (論理値)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"If true then SSSD will download every rule that contains a wildcard in "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"sudoHost attribute."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"This manual page only describes attribute name mapping. For detailed "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"explanation of sudo related attribute semantics, see <citerefentry> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"citerefentry>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"このマニュアルページは属性名マッピングのみを説明します。 sudo に関連する属性"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"セマンティックの詳細な説明は <citerefentry> <refentrytitle>sudoers.ldap</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry> を参照してください"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "AUTOFS OPTIONS"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "AUTOFS オプション"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Some of the defaults for the parameters below are dependent on the LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_autofs_map_master_name (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "The name of the automount master map in LDAP."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: auto.master"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_autofs_map_object_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_autofs_map_object_class (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "The object class of an automount map entry in LDAP."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "LDAP にある automount マップエントリーのオブジェクトクラスです。"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_autofs_map_name (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_autofs_map_name (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "The name of an automount map entry in LDAP."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "LDAP における automount のマップエントリーの名前です。"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Default: nisMapName (rfc2307, autofs_provider=ad), otherwise automountMapName"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_autofs_entry_object_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_autofs_entry_object_class (文字列)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The object class of an automount entry in LDAP. The entry usually "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"corresponds to a mount point."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_autofs_entry_key (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_autofs_entry_key (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"The key of an automount entry in LDAP. The entry usually corresponds to a "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"mount point."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"LDAP にある automount エントリーのキーです。エントリーは一般的にマウントポイ"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_autofs_entry_value (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr "ldap_autofs_entry_value (文字列)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"automountInformation"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<placeholder type=\"variablelist\" id=\"3\"/> <placeholder type="
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"\"variablelist\" id=\"4\"/> <placeholder type=\"variablelist\" id=\"5\"/>"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ADVANCED OPTIONS"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "高度なオプション"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_netgroup_search_base (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "ldap_netgroup_search_base (文字列)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_search_base (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_user_search_base (文字列)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_group_search_base (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "ldap_group_search_base (文字列)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "<note>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If the option <quote>ldap_use_tokengroups</quote> is enabled, the searches "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"against Active Directory will not be restricted and return all groups "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"memberships, even with no GID mapping. It is recommended to disable this "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"feature, if group names are not being displayed correctly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "</note>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ldap_sudo_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_sudo_search_base (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_autofs_search_base (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr "ldap_autofs_search_base (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"These options are supported by LDAP domains, but they should be used with "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"caution. Please include them in your configuration only if you know what you "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\"variablelist\" id=\"1\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:2698 sssd-simple.5.xml:131 sssd-ipa.5.xml:717
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ad.5.xml:1018 sssd-krb5.5.xml:570 sss_rpcidmapd.5.xml:98
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-files.5.xml:71 sssd-session-recording.5.xml:144
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "EXAMPLE"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The following example assumes that SSSD is correctly configured and LDAP is "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"set to one of the domains in the <replaceable>[domains]</replaceable> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"以下の例は、SSSD が正しく設定され、LDAP が <replaceable>[domains]</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"replaceable> セクションにあるドメインのどれかに設定されていると仮定していま"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"id_provider = ldap\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"auth_provider = ldap\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ldap_tls_reqcert = demand\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"cache_credentials = true\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2705 sssd-ldap.5.xml:2723 sssd-simple.5.xml:139
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:725 sssd-ad.5.xml:1026 sssd-sudo.5.xml:56 sssd-krb5.5.xml:579
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#: sssd-files.5.xml:78 sssd-session-recording.5.xml:150
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "<placeholder type=\"programlisting\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<placeholder type=\"programlisting\" id=\"0\"/>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "LDAP ACCESS FILTER EXAMPLE"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The following example assumes that SSSD is correctly configured and to use "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"the ldap_access_order=lockout."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"id_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"auth_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"access_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_access_order = lockout\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap_tls_reqcert = demand\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"cache_credentials = true\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ldap.5.xml:2739 sssd_krb5_locator_plugin.8.xml:61 sssd-simple.5.xml:148
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ad.5.xml:1041 sssd.8.xml:195 sss_seed.8.xml:163
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "NOTES"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The descriptions of some of the configuration options in this manual page "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"are based on the <citerefentry> <refentrytitle>ldap.conf</refentrytitle> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"distribution."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"このマニュアルページにある設定オプションのいくつかの説明は、OpenLDAP 2.4 ディ"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ストリビューションから <citerefentry> <refentrytitle>ldap.conf</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> マニュアルページに基"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "pam_sss"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "pam_sss"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "PAM module for SSSD"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr "SSSD の PAM モジュール"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>pam_sss.so</command> <arg choice='opt'> <replaceable>quiet</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable> </arg> <arg choice='opt'> <replaceable>forward_pass</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable> </arg> <arg choice='opt'> <replaceable>use_first_pass</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable> </arg> <arg choice='opt'> <replaceable>use_authtok</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable> </arg> <arg choice='opt'> <replaceable>retry=N</replaceable> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_unknown_user</replaceable> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_authinfo_unavail</replaceable> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"arg> <arg choice='opt'> <replaceable>domains=X</replaceable> </arg> <arg "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"choice='opt'> <replaceable>allow_missing_name</replaceable> </arg> <arg "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"choice='opt'> <replaceable>prompt_always</replaceable> </arg>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>pam_sss.so</command> is the PAM interface to the System Security "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Services daemon (SSSD). Errors and results are logged through "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>syslog(3)</command> with the LOG_AUTHPRIV facility."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>pam_sss.so</command> は System Security Services daemon (SSSD) への "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"PAM インターフェースです。エラーと結果は <command>syslog(3)</command> を通し"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"て LOG_AUTHPRIV ファシリティでログ記録されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>quiet</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<option>quiet</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Suppress log messages for unknown users."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "不明なユーザーのログメッセージを抑制します。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>forward_pass</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<option>forward_pass</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If <option>forward_pass</option> is set the entered password is put on the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"stack for other PAM modules to use."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>forward_pass</option> が設定されていると、他の PAM モジュールが使用す"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"るために、入力されたパスワードがスタックに置かれます。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>use_first_pass</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "<option>use_first_pass</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The argument use_first_pass forces the module to use a previous stacked "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"modules password and will never prompt the user - if no password is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"available or the password is not appropriate, the user will be denied access."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"引数 use_first_pass は強制的にモジュールが前にスタックされたモジュールのパス"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ワードを使用して、ユーザーに入力させません。パスワードが何も利用可能ではな"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"い、またはパスワードが適切でなければ、ユーザーがアクセスを拒否されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>use_authtok</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "<option>use_authtok</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"When password changing enforce the module to set the new password to the one "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"provided by a previously stacked password module."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"パスワードを変更するとき、モジュールが強制的に新しいパスワードを、前にスタッ"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"クされたパスワードモジュールに設定します。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>retry=N</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "<option>retry=N</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If specified the user is asked another N times for a password if "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"authentication fails. Default is 0."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"指定されていると、認証に失敗した場合にパスワードをあと N 回ユーザーに問い合わ"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"せます。初期値は 0 です。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that this option might not work as expected if the application "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"calling PAM handles the user dialog on its own. A typical example is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>sshd</command> with <option>PasswordAuthentication</option>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"このオプションは、アプリケーションが呼び出す PAM が自身においてユーザーダイア"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ログを処理すると仮定して動作しません。典型的な例は "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>PasswordAuthentication</option> を用いた <command>sshd</command> で"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>ignore_unknown_user</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If this option is specified and the user does not exist, the PAM module will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"return PAM_IGNORE. This causes the PAM framework to ignore this module."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>ignore_authinfo_unavail</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Specifies that the PAM module should return PAM_IGNORE if it cannot contact "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"the SSSD daemon. This causes the PAM framework to ignore this module."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>domains</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Allows the administrator to restrict the domains a particular PAM service is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"allowed to authenticate against. The format is a comma-separated list of "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD domain names, as specified in the sssd.conf file."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"NOTE: Must be used in conjunction with the <quote>pam_trusted_users</quote> "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"and <quote>pam_public_domains</quote> options. Please see the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"manvolnum> </citerefentry> manual page for more information on these two PAM "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"responder options."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "<option>allow_missing_name</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The main purpose of this option is to let SSSD determine the user name based "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"on additional information, e.g. the certificate from a Smartcard."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"auth sufficient pam_sss.so allow_missing_name\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The current use case are login managers which can monitor a Smartcard reader "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"for card events. In case a Smartcard is inserted the login manager will call "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"a PAM stack which includes a line like <placeholder type=\"programlisting\" "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"id=\"0\"/> In this case SSSD will try to determine the user name based on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the content of the Smartcard, returns it to pam_sss which will finally put "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"it on the PAM stack."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "<option>prompt_always</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Always prompt the user for credentials. With this option credentials "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"requested by other PAM modules, typically a password, will be ignored and "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"pam_sss will prompt for credentials again. Based on the pre-auth reply by "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD pam_sss might prompt for a password, a Smartcard PIN or other "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"credentials."
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "MODULE TYPES PROVIDED"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "提供されるモジュール形式"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"All module types (<option>account</option>, <option>auth</option>, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>password</option> and <option>session</option>) are provided."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"すべてのモジュール形式 (<option>account</option>, <option>auth</option>, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>password</option> および <option>session</option>) が提供されます。"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "FILES"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ファイル"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If a password reset by root fails, because the corresponding SSSD provider "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"does not support password resets, an individual message can be displayed. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This message can e.g. contain instructions about how to reset a password."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"対応する SSSD プロバイダーがパスワードリセットをサポートしないため、root によ"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"るパスワードリセットが失敗すると、それぞれのメッセージが表示されます。たとえ"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ば、このメッセージはパスワードをリセットする方法に関する説明があります。"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The message is read from the file <filename>pam_sss_pw_reset_message.LOC</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"filename> where LOC stands for a locale string returned by <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry>. If there is no matching file the content of "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<filename>pam_sss_pw_reset_message.txt</filename> is displayed. Root must be "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the owner of the files and only root may have read and write permissions "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"while all other users must have only read permissions."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"These files are searched in the directory <filename>/etc/sssd/customize/"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"DOMAIN_NAME/</filename>. If no matching file is present a generic message is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"これらのファイルがディレクトリー <filename>/etc/sssd/customize/DOMAIN_NAME/</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"filename> において検索されます。一致するファイルがなければ、一般的なメッセー"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "sssd_krb5_locator_plugin"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "sssd_krb5_locator_plugin"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Kerberos locator plugin"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The Kerberos locator plugin <command>sssd_krb5_locator_plugin</command> is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"used by the Kerberos provider of <citerefentry> <refentrytitle>sssd</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to tell the Kerberos "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"libraries what Realm and which KDC to use. Typically this is done in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"manvolnum> </citerefentry> which is always read by the Kerberos libraries. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"To simplify the configuration the Realm and the KDC can be defined in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"manvolnum> </citerefentry> as described in <citerefentry> "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"</citerefentry> puts the Realm and the name or IP address of the KDC into "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the environment variables SSSD_KRB5_REALM and SSSD_KRB5_KDC respectively. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"When <command>sssd_krb5_locator_plugin</command> is called by the kerberos "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"libraries it reads and evaluates these variables and returns them to the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"</citerefentry> は、レルム、および KDC の名前または IP アドレスを、それぞれ "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD_KRB5_REALM および SSSD_KRB5_KDC の中に置きます。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<command>sssd_krb5_locator_plugin</command> が Kerberos ライブラリーにより呼"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"び出されるとき、それがこれらの変数を読み込み、評価し、ライブラリーに返しま"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Not all Kerberos implementations support the use of plugins. If "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<command>sssd_krb5_locator_plugin</command> is not available on your system "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"you have to edit /etc/krb5.conf to reflect your Kerberos setup."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"すべての Kerberos 実装がプラグインの使用をサポートしているとは限りません。 "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>sssd_krb5_locator_plugin</command> がシステムにおいて利用可能でなけ"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"れば、Kerberos の構築を反映するように /etc/krb5.conf を編集する必要がありま"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"debug messages will be sent to stderr."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"環境変数 SSSD_KRB5_LOCATOR_DEBUG に何らかの値が設定されていると、デバッグメッ"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"セージが標準エラーに送られます。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"If the environment variable SSSD_KRB5_LOCATOR_DISABLE is set to any value "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the plugin is disabled and will just return KRB5_PLUGIN_NO_HANDLE to the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sssd-simple"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "sssd-simple"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "the configuration file for SSSD's 'simple' access-control provider"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "SSSD の 'simple' アクセス制御プロバイダーの設定ファイルです。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This manual page describes the configuration of the simple access-control "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"provider for <citerefentry> <refentrytitle>sssd</refentrytitle> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry>. For a detailed syntax reference, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refer to the <quote>FILE FORMAT</quote> section of the <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> manual page."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"このマニュアルは <citerefentry> <refentrytitle>sssd</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> に対して簡単なアクセス制御の設定を説"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"明しています。詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> マニュアルページの <quote>ファイル形"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"式</quote> セクションを参照してください。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The simple access provider grants or denies access based on an access or "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"deny list of user or group names. The following rules apply:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"シンプルアクセスプロバイダーは、ユーザー名またはグループ名のアクセスまたは拒"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"否の一覧に基づいてアクセスを許可または拒否します。以下の例を適用します:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "If all lists are empty, access is granted"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "すべての一覧が空白ならば、アクセスが認められます"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"If any list is provided, the order of evaluation is allow,deny. This means "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"that any matching deny rule will supersede any matched allow rule."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"何らかの一覧が提供されていると、許可(allow)、拒否(deny)の順に評価されま"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"す。拒否ルールに一致するすべてのものは、許可ルールに一致するすべてのものを更"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"新することを意味します。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"If either or both \"allow\" lists are provided, all users are denied unless "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"they appear in the list."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"\"allow\" 一覧が提供されていると、すべてのユーザーはこの一覧に表れなければ拒"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"If only \"deny\" lists are provided, all users are granted access unless "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"they appear in the list."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"\"deny\" 一覧のみが提供されていると、ユーザーがこの一覧に表れない限り、すべて"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"のユーザーがアクセスを許可されます。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "simple_allow_users (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "simple_allow_users (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Comma separated list of users who are allowed to log in."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "ログインが許可されたユーザーのカンマ区切り一覧です。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "simple_deny_users (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "simple_deny_users (文字列)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Comma separated list of users who are explicitly denied access."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "アクセスが明示的に拒否されたユーザーのカンマ区切り一覧です。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "simple_allow_groups (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "simple_allow_groups (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Comma separated list of groups that are allowed to log in. This applies only "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"to groups within this SSSD domain. Local groups are not evaluated."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ログインが許可されたグループのカンマ区切り一覧です。この SSSD ドメインの中の"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"グループのみに適用されます。ローカルグループは評価されません。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "simple_deny_groups (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "simple_deny_groups (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Comma separated list of groups that are explicitly denied access. This "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"applies only to groups within this SSSD domain. Local groups are not "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"アクセスが明示的に拒否されたグループのカンマ区切り一覧です。この SSSD ドメイ"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ンの中のグループのみに適用されます。ローカルグループは評価されません。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd-simple.5.xml:70 sssd-ipa.5.xml:76 sssd-ad.5.xml:100
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Refer to the section <quote>DOMAIN SECTIONS</quote> of the <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry> manual page for details on the configuration of an SSSD "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"domain. <placeholder type=\"variablelist\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"SSSD ドメインの設定に関する詳細は <citerefentry> <refentrytitle>sssd.conf</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> マニュアルページの "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>ドメインセクション</quote> のセクションを参照してください。 "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Specifying no values for any of the lists is equivalent to skipping it "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"entirely. Beware of this while generating parameters for the simple provider "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"using automated scripts."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Please note that it is an configuration error if both, simple_allow_users "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"and simple_deny_users, are defined."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"simple_allow_users と simple_deny_users がどちらも定義されると、設定エラーに"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"なることに注意してください。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The following example assumes that SSSD is correctly configured and example."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This examples shows only the simple access provider-specific options."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"以下の例は、SSSD が正しく設定され、example.com が <replaceable>[sssd]</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"replaceable> セクションにあるドメインの 1 つであると仮定します。この例はアク"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"セスプロバイダー固有の簡単なオプションのみを示します。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"access_provider = simple\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"simple_allow_users = user1, user2\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The complete group membership hierarchy is resolved before the access check, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"thus even nested groups can be included in the access lists. Please be "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"aware that the <quote>ldap_group_nesting_level</quote> option may impact the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"results and should be set to a sufficient value. (<citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>) option."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sss-certmap"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SSSD Certificate Matching and Mapping Rules"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The manual page describes the rules which can be used by SSSD and other "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"components to match X.509 certificates and map them to accounts."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Each rule has four components, a <quote>priority</quote>, a <quote>matching "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"rule</quote>, a <quote>mapping rule</quote> and a <quote>domain list</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"quote>. All components are optional. A missing <quote>priority</quote> will "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"add the rule with the lowest priority. The default <quote>matching rule</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"quote> will match certificates with the digitalSignature key usage and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"clientAuth extended key usage. If the <quote>mapping rule</quote> is empty "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the certificates will be searched in the userCertificate attribute as DER "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"encoded binary. If no domains are given only the local domain will be "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "RULE COMPONENTS"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "PRIORITY"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The rules are processed by priority while the number '0' (zero) indicates "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the highest priority. The higher the number the lower is the priority. A "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"missing value indicates the lowest priority."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Internally the priority is treated as unsigned 32bit integer, using a "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"priority value larger than 4294967295 will cause an error."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "MATCHING RULE"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The matching rule is used to select a certificate to which the mapping rule "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"should be applied. It uses a system similar to the one used by "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>pkinit_cert_match</quote> option of MIT Kerberos. It consists of a "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"keyword enclosed by '<' and '>' which identified a certain part of the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"certificate and a pattern which should be found for the rule to match. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Multiple keyword pattern pairs can be either joined with '&&' (and) "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"or '||' (or)."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "<SUBJECT>regular-expression"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"With this a part or the whole subject name of the certificate can be "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"matched. For the matching POSIX Extended Regular Expression syntax is used, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"see regex(7) for details."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"For the matching the subject name stored in the certificate in DER encoded "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ASN.1 is converted into a string according to RFC 4514. This means the most "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"specific name component comes first. Please note that not all possible "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attribute names are covered by RFC 4514. The names included are 'CN', 'L', "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"'ST', 'O', 'OU', 'C', 'STREET', 'DC' and 'UID'. Other attribute names might "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"be shown differently on different platform and by different tools. To avoid "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"confusion those attribute names are best not used or covered by a suitable "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"regular-expression."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Example: <SUBJECT>.*,DC=MY,DC=DOMAIN"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "<ISSUER>regular-expression"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"With this a part or the whole issuer name of the certificate can be matched. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"All comments for <SUBJECT> apply her as well."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Example: <ISSUER>^CN=My-CA,DC=MY,DC=DOMAIN$"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "<KU>key-usage"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option can be used to specify which key usage values the certificate "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"should have. The following values can be used in a comma separated list:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "digitalSignature"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "nonRepudiation"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "keyEncipherment"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "dataEncipherment"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "keyAgreement"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "keyCertSign"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "cRLSign"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "encipherOnly"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "decipherOnly"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A numerical value in the range of a 32bit unsigned integer can be used as "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"well to cover special use cases."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Example: <KU>digitalSignature,keyEncipherment"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<EKU>extended-key-usage"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option can be used to specify which extended key usage the certificate "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"should have. The following value can be used in a comma separated list:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "serverAuth"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "clientAuth"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "codeSigning"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "emailProtection"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "timeStamping"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "OCSPSigning"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "KPClientAuth"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "pkinit"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "msScLogin"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Extended key usages which are not listed above can be specified with their "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"OID in dotted-decimal notation."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Example: <EKU>clientAuth,1.3.6.1.5.2.3.4"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "<SAN>regular-expression"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"To be compatible with the usage of MIT Kerberos this option will match the "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Kerberos principals in the PKINIT or AD NT Principal SAN as <SAN:"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Principal> does."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Example: <SAN>.*@MY\\.REALM"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "<SAN:Principal>regular-expression"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Match the Kerberos principals in the PKINIT or AD NT Principal SAN."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Example: <SAN:Principal>.*@MY\\.REALM"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "<SAN:ntPrincipalName>regular-expression"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Match the Kerberos principals from the AD NT Principal SAN."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Example: <SAN:ntPrincipalName>.*@MY.AD.REALM"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "<SAN:pkinit>regular-expression"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "Match the Kerberos principals from the PKINIT SAN."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Example: <SAN:ntPrincipalName>.*@MY\\.PKINIT\\.REALM"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:dotted-decimal-oid>regular-expression"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Take the value of the otherName SAN component given by the OID in dotted-"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"decimal notation, interpret it as string and try to match it against the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"regular expression."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:1.2.3.4>test"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:otherName>base64-string"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Do a binary match with the base64 encoded blob against all otherName SAN "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"components. With this option it is possible to match against custom "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"otherName components with special encodings which could not be treated as "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:otherName>MTIz"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:rfc822Name>regular-expression"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Match the value of the rfc822Name SAN."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:rfc822Name>.*@email\\.domain"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:dNSName>regular-expression"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Match the value of the dNSName SAN."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Example: <SAN:dNSName>.*\\.my\\.dns\\.domain"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<SAN:x400Address>base64-string"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Binary match the value of the x400Address SAN."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Example: <SAN:x400Address>MTIz"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<SAN:directoryName>regular-expression"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Match the value of the directoryName SAN. The same comments as given for <"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ISSUER> and <SUBJECT> apply here as well."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:directoryName>.*,DC=com"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:ediPartyName>base64-string"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Binary match the value of the ediPartyName SAN."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Example: <SAN:ediPartyName>MTIz"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:uniformResourceIdentifier>regular-expression"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Match the value of the uniformResourceIdentifier SAN."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:uniformResourceIdentifier>URN:.*"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:iPAddress>regular-expression"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Match the value of the iPAddress SAN."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:iPAddress>192\\.168\\..*"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<SAN:registeredID>regular-expression"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Match the value of the registeredID SAN as dotted-decimal string."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Example: <SAN:registeredID>1\\.2\\.3\\..*"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The available options are: <placeholder type=\"variablelist\" id=\"0\"/>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "MAPPING RULE"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The mapping rule is used to associate a certificate with one or more "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"accounts. A Smartcard with the certificate and the matching private key can "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"then be used to authenticate as one of those accounts."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Currently SSSD basically only supports LDAP to lookup user information (the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"exception is the proxy provider which is not of relevance here). Because of "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"this the mapping rule is based on LDAP search filter syntax with templates "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"to add certificate content to the filter. It is expected that the filter "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"will only contain the specific data needed for the mapping and that the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"caller will embed it in another filter to do the actual search. Because of "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"this the filter string should start and stop with '(' and ')' respectively."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"In general it is recommended to use attributes from the certificate and add "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"them to special attributes to the LDAP user object. E.g. the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"'altSecurityIdentities' attribute in AD or the 'ipaCertMapData' attribute "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"for IPA can be used."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This should be preferred to read user specific data from the certificate "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"like e.g. an email address and search for it in the LDAP server. The reason "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is that the user specific data in LDAP might change for various reasons "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"would break the mapping. On the other hand it would be hard to break the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"mapping on purpose for a specific user."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "{issuer_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the full issuer DN converted to a string according to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the '_x500' prefix should be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss-certmap.5.xml:383 sss-certmap.5.xml:409
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The conversion options starting with 'ad_' will use attribute names as used "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"by AD, e.g. 'S' instead of 'ST'."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss-certmap.5.xml:387 sss-certmap.5.xml:413
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The conversion options starting with 'nss_' will use attribute names as used "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss-certmap.5.xml:391 sss-certmap.5.xml:417
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The default conversion option is 'nss', i.e. attribute names according to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"NSS and LDAP/RFC 4514 ordering."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Example: (ipacertmapdata=X509:<I>{issuer_dn!ad}<S>{subject_dn!"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "{subject_dn[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This template will add the full subject DN converted to string according to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"RFC 4514. If X.500 ordering (most specific RDN comes last) an option with "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the '_x500' prefix should be used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Example: (ipacertmapdata=X509:<I>{issuer_dn!nss_x500}<S>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"{subject_dn!nss_x500})"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "{cert[!(bin|base64)]}"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the whole DER encoded certificate as a string to the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"search filter. Depending on the conversion option the binary certificate is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"either converted to an escaped hex sequence '\\xx' or base64. The escaped "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"hex sequence is the default and can e.g. be used with the LDAP attribute "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"'userCertificate;binary'."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: (userCertificate;binary={cert!bin})"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_principal[.short_name]}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This template will add the Kerberos principal which is taken either from the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SAN used by pkinit or the one used by AD. The 'short_name' component "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"represents the first part of the principal before the '@' sign."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Example: (|(userPrincipal={subject_principal})"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(samAccountName={subject_principal.short_name}))"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_pkinit_principal[.short_name]}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This template will add the Kerberos principal which is given by the SAN used "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"by pkinit. The 'short_name' component represents the first part of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"principal before the '@' sign."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Example: (|(userPrincipal={subject_pkinit_principal})"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"(uid={subject_pkinit_principal.short_name}))"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "{subject_nt_principal[.short_name]}"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"This template will add the Kerberos principal which is given by the SAN used "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"by AD. The 'short_name' component represent the first part of the principal "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"before the '@' sign."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_rfc822_name[.short_name]}"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This template will add the string which is stored in the rfc822Name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"component of the SAN, typically an email address. The 'short_name' component "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"represents the first part of the address before the '@' sign."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Example: (|(mail={subject_rfc822_name})(uid={subject_rfc822_name."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"short_name}))"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_dns_name[.short_name]}"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the string which is stored in the dNSName component "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"of the SAN, typically a fully-qualified host name. The 'short_name' "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"component represents the first part of the name before the first '.' sign."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Example: (|(fqdn={subject_dns_name})(host={subject_dns_name.short_name}))"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_uri}"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This template will add the string which is stored in the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"uniformResourceIdentifier component of the SAN."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Example: (uri={subject_uri})"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_ip_address}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the string which is stored in the iPAddress component "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: (ip={subject_ip_address})"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_x400_address}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the value which is stored in the x400Address "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"component of the SAN as escaped hex sequence."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Example: (attr:binary={subject_x400_address})"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"{subject_directory_name[!((ad|ad_x500)|ad_ldap|nss_x500|(nss|nss_ldap))]}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the DN string of the value which is stored in the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directoryName component of the SAN."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: (orig_dn={subject_directory_name})"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "{subject_ediparty_name}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This template will add the value which is stored in the ediPartyName "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"component of the SAN as escaped hex sequence."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: (attr:binary={subject_ediparty_name})"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "{subject_registered_id}"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This template will add the OID which is stored in the registeredID component "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of the SAN as as dotted-decimal string."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example: (oid={subject_registered_id})"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The templates to add certificate data to the search filter are based on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Python-style formatting strings. They consist of a keyword in curly braces "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"with an optional sub-component specifier separated by a '.' or an optional "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"conversion/formatting option separated by a '!'. Allowed values are: "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "DOMAIN LIST"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"If the domain list is not empty users mapped to a given certificate are not "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"only searched in the local domain but in the listed domains as well as long "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"as they are know by SSSD. Domains not know to SSSD will be ignored."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "sssd-ipa"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "sssd-ipa"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "SSSD IPA provider"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"This manual page describes the configuration of the IPA provider for "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"このマニュアルページは <citerefentry> <refentrytitle>sssd</refentrytitle> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> に対する IPA プロバイダーの設定を説"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"明しています。詳細な構文の参考資料は <citerefentry> <refentrytitle>sssd."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"conf</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> マニュアルペー"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ジの <quote>ファイル形式</quote> を参照してください。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The IPA provider is a back end used to connect to an IPA server. (Refer to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the freeipa.org web site for information about IPA servers.) This provider "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"requires that the machine be joined to the IPA domain; configuration is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"almost entirely self-discovered and obtained directly from the server."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"IPA プロバイダーは IPA サーバーに接続するために使用されるバックエンドです。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"(IPA サーバーに関する詳細は freeipa.org のウェブサイトを参照してください。)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"このプロバイダーは、マシンが IPA ドメインに参加していて、設定がすでに全体的に"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"自己検索され、サーバーから直接取得されている必要があります。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The IPA provider enables SSSD to use the <citerefentry> <refentrytitle>sssd-"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> identity "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"provider and the <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> authentication provider with "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optimizations for IPA environments. The IPA provider accepts the same "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"options used by the sssd-ldap and sssd-krb5 providers with some exceptions. "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"However, it is neither necessary nor recommended to set these options."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The IPA provider primarily copies the traditional ldap and krb5 provider "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"default options with some exceptions, the differences are listed in the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>MODIFIED DEFAULT OPTIONS</quote> section."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"As an access provider, the IPA provider uses HBAC (host-based access "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"control) rules. Please refer to freeipa.org for more information about "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"HBAC. No configuration of access provider is required on the client side."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The IPA provider will use the PAC responder if the Kerberos tickets of users "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from trusted realms contain a PAC. To make configuration easier the PAC "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"responder is started automatically if the IPA ID provider is configured."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ipa_domain (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ipa_domain (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies the name of the IPA domain. This is optional. If not provided, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the configuration domain name is used."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"IPA ドメインの名前を指定します。これはオプションです。提供されなければ、設定"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ドメイン名が使用されます。"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ipa_server, ipa_backup_server (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ipa_server, ipa_backup_server (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The comma-separated list of IP addresses or hostnames of the IPA servers to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"which SSSD should connect in the order of preference. For more information "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"on failover and server redundancy, see the <quote>FAILOVER</quote> section. "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"This is optional if autodiscovery is enabled. For more information on "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ipa_hostname (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ipa_hostname (文字列)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "Optional. May be set on machines where the hostname(5) does not reflect "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "the fully qualified name used in the IPA domain to identify this host."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Optional. May be set on machines where the hostname(5) does not reflect the "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"fully qualified name used in the IPA domain to identify this host. The "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"hostname must be fully qualified."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"オプションです。hostname(5) がこのホストを識別するために IPA ドメインにおいて"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"使用される完全修飾名を反映しないマシンにおいて設定されます。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_update (boolean)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "dyndns_update (論理値)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Optional. This option tells SSSD to automatically update the DNS server "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"built into FreeIPA with the IP address of this client. The update is secured "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"using GSS-TSIG. The IP address of the IPA LDAP connection is used for the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"updates, if it is not otherwise specified by using the <quote>dyndns_iface</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"quote> option."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"the default Kerberos realm must be set properly in /etc/krb5.conf"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"注: (RHEL5 のような) 古いシステムにおいて、この動作が正しく機能するためには、"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"デフォルトの Kerberos レルムが /etc/krb5.conf において正しく設定されている必"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_update</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_update</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis> in their config file."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_ttl (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "dyndns_ttl (整数)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The TTL to apply to the client DNS record when updating it. If "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"dyndns_update is false this has no effect. This will override the TTL "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"serverside if set by an administrator."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_ttl</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_ttl</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"emphasis> in their config file."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 1200 (seconds)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "初期値: 1200 (秒)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "dyndns_iface (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "dyndns_iface (文字列)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Optional. Applicable only when dyndns_update is true. Choose the interface "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"or a list of interfaces whose IP addresses should be used for dynamic DNS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"updates. Special value <quote>*</quote> implies that IPs from all interfaces "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"should be used."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_iface</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis> in their config file."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for IPA LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Example: dyndns_iface = em1, vnet1, vnet2"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_auth (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Whether the nsupdate utility should use GSS-TSIG authentication for secure "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"updates with the DNS server, insecure updates can be sent by setting this "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"option to 'none'."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: GSS-TSIG"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ipa_enable_dns_sites (boolean)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ipa_enable_dns_sites (論理値)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Enables DNS sites - location based service discovery."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "DNS サイトの有効化 - 位置情報に基づいたサービス探索。"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"If true and service discovery (see Service Discovery paragraph at the bottom "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"of the man page) is enabled, then the SSSD will first attempt location "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"based discovery using a query that contains \"_location.hostname.example.com"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"\" and then fall back to traditional SRV discovery. If the location based "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"discovery succeeds, the IPA servers located with the location based "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"discovery are treated as primary servers and the IPA servers located using "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"the traditional SRV discovery are used as back up servers"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_refresh_interval (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "dyndns_refresh_interval (整数)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"How often should the back end perform periodic DNS update in addition to the "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"automatic update performed when the back end goes online. This option is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optional and applicable only when dyndns_update is true."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dyndns_update_ptr (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "dyndns_update_ptr (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Whether the PTR record should also be explicitly updated when updating the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"client's DNS records. Applicable only when dyndns_update is true."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option should be False in most IPA deployments as the IPA server "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"generates the PTR records automatically when forward records are changed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: False (disabled)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: False (無効)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dyndns_force_tcp (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "dyndns_force_tcp (論理値)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Whether the nsupdate utility should default to using TCP for communicating "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"with the DNS server."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"nsupdate ユーティリティが DNS サーバーと通信するために TCP を標準で使用するか"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: False (let nsupdate choose the protocol)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dyndns_server (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The DNS server to use when performing a DNS update. In most setups, it's "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"recommended to leave this option unset."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Setting this option makes sense for environments where the DNS server is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"different from the identity server."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that this option will be only used in fallback attempt when "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"previous attempt using autodetected settings failed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: None (let nsupdate choose the server)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#| msgid "ipa_host_search_base (string)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ipa_deskprofile_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ipa_host_search_base (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#| "Optional. Use the given string as search base for HBAC related objects."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Optional. Use the given string as search base for Desktop Profile related "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。与えられた文字列を HBAC 関連オブジェクトに対する検索ベースと"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Use base DN"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: ベース DN を使用します"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_hbac_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ipa_hbac_search_base (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Optional. Use the given string as search base for HBAC related objects."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。与えられた文字列を HBAC 関連オブジェクトに対する検索ベースと"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_host_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ipa_host_search_base (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Optional. Use the given string as search base for host objects."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。ホストオブジェクトの検索ベースとして与えられた文字列を使用し"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:344 sssd-ipa.5.xml:363 sssd-ipa.5.xml:382 sssd-ipa.5.xml:401
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"See <quote>ldap_search_base</quote> for information about configuring "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"multiple search bases."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"複数の検索ベースを設定することの詳細は <quote>ldap_search_base</quote> を参照"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:349 sssd-ipa.5.xml:368 include/ldap_search_bases.xml:27
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: the value of <emphasis>ldap_search_base</emphasis>"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr "初期値: <emphasis>ldap_search_base</emphasis> の値"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "ipa_selinux_search_base (string)"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr "ipa_selinux_search_base (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Optional. Use the given string as search base for SELinux user maps."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。与えられた文字列を SELinux ユーザーマップに対する検索ベースと"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_subdomains_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ipa_subdomains_search_base (文字列)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Optional. Use the given string as search base for trusted domains."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。信頼されたドメインに対する検索ベースとして、与えられた文字列"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: <emphasis>cn=trusts,%basedn</emphasis> の値"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_master_domain_search_base (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ipa_master_domain_search_base (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Optional. Use the given string as search base for master domain object."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr "初期値: <emphasis>cn=ad,cn=etc,%basedn</emphasis> の値"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_views_search_base (string)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Optional. Use the given string as search base for views containers."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The name of the Kerberos realm. This is optional and defaults to the value "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"of <quote>ipa_domain</quote>."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Kerberos レルムの名前です。これはオプションで、初期値は <quote>ipa_domain</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The name of the Kerberos realm has a special meaning in IPA - it is "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"converted into the base DN to use for performing LDAP operations."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"IPA において特別な意味を持つ Kerberos レルムの名前です。LDAP 操作を実行するた"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"めに使用するベース DN に変換されます。"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "krb5_confd_path (string)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Absolute path of a directory where SSSD should place Kerberos configuration "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"To disable the creation of the configuration snippets set the parameter to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#| msgid "ipa_hbac_refresh (integer)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "ipa_deskprofile_refresh (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ipa_hbac_refresh (整数)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The amount of time between lookups of the Desktop Profile rules against the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"IPA server. This will reduce the latency and load on the IPA server if there "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"are many desktop profiles requests made in a short period."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sssd-ipa.5.xml:475 sssd-ipa.5.xml:505 sssd-ipa.5.xml:521 sssd-ad.5.xml:408
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 5 (seconds)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "初期値: 5 (秒)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "ldap_sudo_full_refresh_interval (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_deskprofile_request_interval (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ldap_sudo_full_refresh_interval (整数)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The amount of time between lookups of the Desktop Profile rules against the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"IPA server in case the last request did not return any rule."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#| msgid "Default: 900 (15 minutes)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 60 (minutes)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: 900 (15 分)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_hbac_refresh (integer)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "ipa_hbac_refresh (整数)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"The amount of time between lookups of the HBAC rules against the IPA server. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This will reduce the latency and load on the IPA server if there are many "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"access-control requests made in a short period."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "ipa_hbac_selinux (integer)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "ipa_hbac_selinux (整数)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The amount of time between lookups of the SELinux maps against the IPA "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"server. This will reduce the latency and load on the IPA server if there are "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"many user login requests made in a short period."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ipa_server_mode (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ipa_server_mode (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option will be set by the IPA installer (ipa-server-install) "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"automatically and denotes if SSSD is running on an IPA server or not."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"On an IPA server SSSD will lookup users and groups from trusted domains "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directly while on a client it will ask an IPA server."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_automount_location (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ipa_automount_location (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The automounter location this IPA client will be using"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "この IPA クライアントが使用する automounter の場所です"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: The location named \"default\""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "初期値: \"default\" という名前の場所"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "VIEWS AND OVERRIDES"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_view_class (string)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Objectclass of the view container."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: nsContainer"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "ipa_view_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "Name of the attribute holding the name of the view."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "ipa_override_object_class (string)"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Objectclass of the override objects."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "Default: ipaOverrideAnchor"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "ipa_anchor_uuid (string)"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Name of the attribute containing the reference to the original object in a "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"remote domain."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: ipaAnchorUUID"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ipa_user_override_object_class (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Name of the objectclass for user overrides. It is used to determine if the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"found override object is related to a user or a group."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "User overrides can contain attributes given by"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "ldap_user_name"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "ldap_user_uid_number"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gid_number"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gecos"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_home_directory"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shell"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ssh_public_key"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: ipaUserOverride"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ipa_group_override_object_class (string)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Name of the objectclass for group overrides. It is used to determine if the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"found override object is related to a user or a group."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Group overrides can contain attributes given by"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "ldap_group_name"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "ldap_group_gid_number"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "Default: ipaGroupOverride"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD can handle views and overrides which are offered by FreeIPA 4.1 and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"later version. Since all paths and objectclasses are fixed on the server "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"side there is basically no need to configure anything. For completeness the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"related options are listed here with their default values. <placeholder "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"type=\"variablelist\" id=\"0\"/>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "SUBDOMAINS PROVIDER"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"The IPA subdomains provider behaves slightly differently if it is configured "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"explicitly or implicitly."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If the option 'subdomains_provider = ipa' is found in the domain section of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"sssd.conf, the IPA subdomains provider is configured explicitly, and all "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"subdomain requests are sent to the IPA server if necessary."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"'subdomains_provider = ipa' オプションが sssd.conf のドメインのセクションに見"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"つかれば、IPA サブドメインプロバイダーが明示的に設定されます。すべてのサブド"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"メインのリクエストが必要に応じて IPA サーバーに送られます。"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"If the option 'subdomains_provider' is not set in the domain section of sssd."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"conf but there is the option 'id_provider = ipa', the IPA subdomains "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"provider is configured implicitly. In this case, if a subdomain request "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"fails and indicates that the server does not support subdomains, i.e. is not "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"configured for trusts, the IPA subdomains provider is disabled. After an "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"hour or after the IPA provider goes online, the subdomains provider is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"enabled again."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"The following example assumes that SSSD is correctly configured and example."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"This examples shows only the ipa provider-specific options."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"以下の例は、SSSD が正しく設定され、example.com が <replaceable>[sssd]</"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"replaceable> セクションにあるドメインの 1 つであることを仮定しています。この"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"例は IPA プロバイダー固有のオプションのみを示しています。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"id_provider = ipa\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ipa_hostname = myhost.example.com\n"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-ad"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "sssd-ad"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SSSD Active Directory provider"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of the AD provider for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The AD provider is a back end used to connect to an Active Directory server. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"This provider requires that the machine be joined to the AD domain and a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"keytab is available. Back end communication occurs over a GSSAPI-encrypted "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"channel, SSL/TLS options should not be used with the AD provider and will be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"superceded by Kerberos usage."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"The AD provider supports connecting to Active Directory 2008 R2 or later. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Earlier versions may work, but are unsupported."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"The AD provider can be used to get user information and authenticate users "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"from trusted domains. Currently only trusted domains in the same forest are "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"recognized. In addition servers from trusted domains are always auto-"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"The AD provider enables SSSD to use the <citerefentry> <refentrytitle>sssd-"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> identity "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"provider and the <citerefentry> <refentrytitle>sssd-krb5</refentrytitle> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> authentication provider with "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"optimizations for Active Directory environments. The AD provider accepts the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"same options used by the sssd-ldap and sssd-krb5 providers with some "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"exceptions. However, it is neither necessary nor recommended to set these "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The AD provider primarily copies the traditional ldap and krb5 provider "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"default options with some exceptions, the differences are listed in the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>MODIFIED DEFAULT OPTIONS</quote> section."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The AD provider can also be used as an access, chpass, sudo and autofs "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"provider. No configuration of the access provider is required on the client "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_id_mapping = False\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_id_mapping = False\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"By default, the AD provider will map UID and GID values from the objectSID "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameter in Active Directory. For details on this, see the <quote>ID "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"MAPPING</quote> section below. If you want to disable ID mapping and instead "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"rely on POSIX attributes defined in Active Directory, you should set "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/> In order to retrieve users "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"and groups using POSIX attributes from trusted domains, the AD administrator "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"must make sure that the POSIX attributes are replicated to the Global "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Users, groups and other entities served by SSSD are always treated as case-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"insensitive in the AD provider for compatibility with Active Directory's "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"LDAP implementation."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ad_domain (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ad_domain (文字列)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Specifies the name of the Active Directory domain. This is optional. If not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"provided, the configuration domain name is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Active Directory ドメインの名前を指定します。これはオプションです。指定されな"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ければ、設定のドメイン名が使用されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For proper operation, this option should be specified as the lower-case "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"version of the long version of the Active Directory domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"正しい動作のために、このオプションは Active Directory ドメインの長いバージョ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ンの小文字バージョンとして指定されます。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The short domain name (also known as the NetBIOS or the flat name) is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"autodetected by the SSSD."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_enabled_domains (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"A comma-separated list of enabled Active Directory domains. If provided, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD will ignore any domains not listed in this option. If left unset, all "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains from the AD forest will be available."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"ad_enabled_domains = sales.example.com, eng.example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For proper operation, this option must be specified in all lower-case and as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the fully qualified domain name of the Active Directory domain. For example: "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<placeholder type=\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The short domain name (also known as the NetBIOS or the flat name) will be "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"autodetected by SSSD."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_server, ad_backup_server (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ad_server, ad_backup_server (文字列)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The comma-separated list of hostnames of the AD servers to which SSSD should "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"connect in order of preference. For more information on failover and server "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"redundancy, see the <quote>FAILOVER</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This is optional if autodiscovery is enabled. For more information on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note: Trusted domains will always auto-discover servers even if the primary "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"server is explicitly defined in the ad_server option."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_hostname (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ad_hostname (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Optional. May be set on machines where the hostname(5) does not reflect the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"fully qualified name used in the Active Directory domain to identify this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"オプションです。hostname(5) が Active Directory ドメインにおいて使用される完"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"全修飾名を反映しないマシンにおいてマシンに設定されるかもしれません。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This field is used to determine the host principal in use in the keytab. It "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"must match the hostname for which the keytab was issued."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"この項目はキーテーブルにおいて使用中のホストプリンシパルを決定するために使用"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"されます。キーテーブルが発行されたホスト名と一致する必要があります。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_enable_dns_sites (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ad_enable_dns_sites (論理値)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If true and service discovery (see Service Discovery paragraph at the bottom "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of the man page) is enabled, the SSSD will first attempt to discover the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Active Directory server to connect to using the Active Directory Site "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Discovery and fall back to the DNS SRV records if no AD site is found. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"DNS SRV configuration, including the discovery domain, is used during site "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"discovery as well."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ad_access_filter (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option specifies LDAP access control filter that the user must match in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"order to be allowed access. Please note that the <quote>access_provider</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"quote> option must be explicitly set to <quote>ad</quote> in order for this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"option to have an effect."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The option also supports specifying different filters per domain or forest. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This extended filter would consist of: <quote>KEYWORD:NAME:FILTER</quote>. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The keyword can be either <quote>DOM</quote>, <quote>FOREST</quote> or "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"If the keyword equals to <quote>DOM</quote> or is missing, then <quote>NAME</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"quote> specifies the domain or subdomain the filter applies to. If the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"keyword equals to <quote>FOREST</quote>, then the filter equals to all "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains from the forest specified by <quote>NAME</quote>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Multiple filters can be separated with the <quote>?</quote> character, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"similarly to how search bases work."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Nested group membership must be searched for using a special OID "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>:1.2.840.113556.1.4.1941:</quote> in addition to the full DOM:domain."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"example.org: syntax to ensure the parser does not attempt to interpret the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"colon characters associated with the OID. If you do not use this OID then "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"nested group membership will not be resolved. See usage example below and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refer here for further information about the OID: <ulink url=\"https://msdn."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"microsoft.com/en-us/library/cc223367.aspx\"> [MS-ADTS] section LDAP "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"extensions</ulink>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The most specific match is always used. For example, if the option specified "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"filter for a domain the user is a member of and a global filter, the per-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domain filter would be applied. If there are more matches with the same "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"specification, the first one is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"# apply filter on domain called dom1 only:\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"# apply filter on domain called dom2 only:\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"# apply filter on forest called EXAMPLE.COM only:\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"# apply filter for a member of a nested group in dom1:\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"DOM:dom1:(memberOf:1.2.840.113556.1.4.1941:=cn=nestedgroup,ou=groups,dc=example,dc=com)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_site (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specify AD site to which client should try to connect. If this option is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"not provided, the AD site will be auto-discovered."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "ad_enable_gc (boolean)"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"By default, the SSSD connects to the Global Catalog first to retrieve users "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"from trusted domains and uses the LDAP port to retrieve group memberships or "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"as a fallback. Disabling this option makes the SSSD only connect to the LDAP "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"port of the current AD server."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please note that disabling Global Catalog support does not disable "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"retrieving users from trusted domains. The SSSD would connect to the LDAP "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"port of trusted domains instead. However, Global Catalog must be used in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"order to resolve cross-domain group memberships."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ad_gpo_access_control (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option specifies the operation mode for GPO-based access control "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"functionality: whether it operates in disabled mode, enforcing mode, or "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"permissive mode. Please note that the <quote>access_provider</quote> option "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"must be explicitly set to <quote>ad</quote> in order for this option to have "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"GPO-based access control functionality uses GPO policy settings to determine "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"whether or not a particular user is allowed to logon to a particular host."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"NOTE: If the operation mode is set to enforcing, it is possible that users "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"that were previously allowed logon access will now be denied logon access "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"(as dictated by the GPO policy settings). In order to facilitate a smooth "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"transition for administrators, a permissive mode is available that will not "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"enforce the access control rules, but will evaluate them and will output a "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"syslog message if access would have been denied. By examining the logs, "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"administrators can then make the necessary changes before setting the mode "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"to enforcing."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "There are three supported values for this option:"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"disabled: GPO-based access control rules are neither evaluated nor enforced."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "enforcing: GPO-based access control rules are evaluated and enforced."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"permissive: GPO-based access control rules are evaluated, but not enforced. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Instead, a syslog message will be emitted indicating that the user would "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"have been denied access if this option's value were set to enforcing."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Default: permissive"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Default: enforcing"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "ad_gpo_cache_timeout (integer)"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"The amount of time between lookups of GPO policy files against the AD "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"server. This will reduce the latency and load on the AD server if there are "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"many access-control requests made in a short period."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "ad_gpo_map_interactive (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"A comma-separated list of PAM service names for which GPO-based access "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"control is evaluated based on the InteractiveLogonRight and "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"DenyInteractiveLogonRight policy settings."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"log on locally\" and \"Deny log on locally\"."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ad_gpo_map_interactive = +my_pam_service, -login\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"It is possible to add another PAM service name to the default set by using "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"the default set by using <quote>-service_name</quote>. For example, in "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>login</quote>) with a custom pam service name (e.g. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>my_pam_service</quote>), you would use the following configuration: "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<placeholder type=\"programlisting\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sssd-ad.5.xml:441 sssd-ad.5.xml:537 sssd-ad.5.xml:583 sssd-ad.5.xml:628
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Default: the default set of PAM service names includes:"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "gdm-fingerprint"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "gdm-password"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "gdm-smartcard"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "lightdm"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ad_gpo_map_remote_interactive (string)"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"A comma-separated list of PAM service names for which GPO-based access "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"control is evaluated based on the RemoteInteractiveLogonRight and "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"DenyRemoteInteractiveLogonRight policy settings."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Note: Using the Group Policy Management Editor this value is called \"Allow "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"log on through Remote Desktop Services\" and \"Deny log on through Remote "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Desktop Services\"."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>sshd</quote>) with a custom pam service name (e.g. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "cockpit"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_gpo_map_network (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"control is evaluated based on the NetworkLogonRight and "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"DenyNetworkLogonRight policy settings."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Access "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"this computer from the network\" and \"Deny access to this computer from the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ad_gpo_map_network = +my_pam_service, -ftp\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"It is possible to add another PAM service name to the default set by using "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"the default set by using <quote>-service_name</quote>. For example, in "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"order to replace a default PAM service name for this logon right (e.g. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>ftp</quote>) with a custom pam service name (e.g. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<quote>my_pam_service</quote>), you would use the following configuration: "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<placeholder type=\"programlisting\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "ad_gpo_map_batch (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"A comma-separated list of PAM service names for which GPO-based access "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"control is evaluated based on the BatchLogonRight and DenyBatchLogonRight "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"policy settings."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"log on as a batch job\" and \"Deny log on as a batch job\"."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ad_gpo_map_batch = +my_pam_service, -crond\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>crond</quote>) with a custom pam service name (e.g. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "crond"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ad_gpo_map_service (string)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"control is evaluated based on the ServiceLogonRight and "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"DenyServiceLogonRight policy settings."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"log on as a service\" and \"Deny log on as a service\"."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ad_gpo_map_service = +my_pam_service\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"It is possible to add a PAM service name to the default set by using <quote>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"+service_name</quote>. Since the default set is empty, it is not possible "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"to remove a PAM service name from the default set. For example, in order to "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"add a custom pam service name (e.g. <quote>my_pam_service</quote>), you "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"would use the following configuration: <placeholder type=\"programlisting\" "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ad_gpo_map_permit (string)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"always granted, regardless of any GPO Logon Rights."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ad_gpo_map_permit = +my_pam_service, -sudo\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"order to replace a default PAM service name for unconditionally permitted "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"access (e.g. <quote>sudo</quote>) with a custom pam service name (e.g. "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "polkit-1"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sudo-i"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "systemd-user"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_gpo_map_deny (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"always denied, regardless of any GPO Logon Rights."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ad_gpo_map_deny = +my_pam_service\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_gpo_default_right (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option defines how access control is evaluated for PAM service names "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that are not explicitly listed in one of the ad_gpo_map_* options. This "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"option can be set in two different manners. First, this option can be set to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"use a default logon right. For example, if this option is set to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"'interactive', it means that unmapped PAM service names will be processed "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"based on the InteractiveLogonRight and DenyInteractiveLogonRight policy "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"settings. Alternatively, this option can be set to either always permit or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"always deny access for unmapped PAM service names."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Supported values for this option include:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "interactive"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "remote_interactive"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "network"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "batch"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "service"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "permit"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: deny"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_maximum_machine_account_password_age (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD will check once a day if the machine account password is older than the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"given age in days and try to renew it. A value of 0 will disable the renewal "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 30 days"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_machine_account_password_renewal_opts (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option should only be used to test the machine account renewal task. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The option expects 2 integers separated by a colon (':'). The first integer "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"defines the interval in seconds how often the task is run. The second "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"specifies the initial timeout in seconds before the task is run for the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"first time after startup."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 86400:750 (24h and 15m)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Optional. This option tells SSSD to automatically update the Active "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Directory DNS server with the IP address of this client. The update is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"secured using GSS-TSIG. As a consequence, the Active Directory administrator "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"only needs to allow secure updates for the DNS zone. The IP address of the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"AD LDAP connection is used for the updates, if it is not otherwise specified "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"by using the <quote>dyndns_iface</quote> option."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: 3600 (seconds)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "初期値: 3600 (秒)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for AD LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"How often should the back end perform periodic DNS update in addition to the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"automatic update performed when the back end goes online. This option is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"optional and applicable only when dyndns_update is true. Note that the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"lowest possible value is 60 seconds in-case if value is provided less than "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"60, parameter will assume lowest value only."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: True"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "初期値: True"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The following example assumes that SSSD is correctly configured and example."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This example shows only the AD provider-specific options."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"以下の例は SSSD が正しく設定され、example.com が <replaceable>[sssd]</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"replaceable> セクションにあるドメインの一つであると仮定しています。この例は "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"AD プロバイダー固有のオプションのみ示してします。"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"id_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"auth_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"chpass_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ad_hostname = client.example.com\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ad_domain = example.com\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"id_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"auth_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"chpass_provider = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ad_hostname = client.example.com\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ad_domain = example.com\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access_provider = ldap\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"ldap_access_order = expire\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ldap_account_expire_policy = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access_provider = ldap\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ldap_access_order = expire\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"ldap_account_expire_policy = ad\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The AD access control provider checks if the account is expired. It has the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"same effect as the following configuration of the LDAP provider: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"However, unless the <quote>ad</quote> access control provider is explicitly "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"configured, the default access provider is <quote>permit</quote>. Please "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"note that if you configure an access provider other than <quote>ad</quote>, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"you need to set all the connection parameters (such as LDAP URIs and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"encryption details) manually."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attribute mapping (nisMap, nisObject, ...) is used, because these attributes "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"are included in the default Active Directory schema."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refmeta><refentrytitle>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16 sssd-session-recording.5.xml:10
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sssd-sudo"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "sssd-sudo"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Configuring sudo with the SSSD back end"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "SSSD バックエンドを用いた sudo の設定法"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This manual page describes how to configure <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Configuring sudo to cooperate with SSSD"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"To enable SSSD as a source for sudo rules, add <emphasis>sss</emphasis> to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the <emphasis>sudoers</emphasis> entry in <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"For example, to configure sudo to first lookup rules in the standard "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sudoers</refentrytitle> <manvolnum>5</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"manvolnum> </citerefentry> file (which should contain rules that apply to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"local users) and then in SSSD, the nsswitch.conf file should contain the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"following line:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sudoers: files sss\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "sudoers: files sss\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"More information about configuring the sudoers search order from the "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"nsswitch.conf file as well as information about the LDAP schema that is used "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"to store sudo rules in the directory can be found in <citerefentry> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> </"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>Note</emphasis>: in order to use netgroups or IPA hostgroups in "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"sudo rules, you also need to correctly set <citerefentry> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<refentrytitle>nisdomainname</refentrytitle> <manvolnum>1</manvolnum> </"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> to your NIS domain name (which equals to IPA domain name when "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"using hostgroups)."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Configuring SSSD to fetch sudo rules"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "sudo ルールを取得するよう SSSD を設定する方法"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"All configuration that is needed on SSSD side is to extend the list of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>services</emphasis> with \"sudo\" in [sssd] section of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"manvolnum> </citerefentry>. To speed up the LDAP lookups, you can also set "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"search base for sudo rules using <emphasis>ldap_sudo_search_base</emphasis> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"The following example shows how to configure SSSD to download sudo rules "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from an LDAP server."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"config_file_version = 2\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"services = nss, pam, sudo\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"domains = EXAMPLE\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"id_provider = ldap\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"sudo_provider = ldap\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ldap_uri = ldap://example.com\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"config_file_version = 2\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"services = nss, pam, sudo\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"domains = EXAMPLE\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"id_provider = ldap\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"sudo_provider = ldap\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ldap_uri = ldap://example.com\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/> <phrase condition="
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"\"have_systemd\"> It's important to note that on platforms where systemd is "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"supported there's no need to add the \"sudo\" provider to the list of "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"services, as it became optional. However, sssd-sudo.socket must be enabled "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"instead. </phrase>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"When SSSD is configured to use IPA as the ID provider, the sudo provider is "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"automatically enabled. The sudo search base is configured to use the IPA "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"native LDAP tree (cn=sudo,$SUFFIX). If any other search base is defined in "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"sssd.conf, this value will be used instead. The compat tree (ou=sudoers,"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"$SUFFIX) is no longer required for IPA sudo functionality."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "The SUDO rule caching mechanism"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "SUDO ルールキャッシュメカニズム"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"The biggest challenge, when developing sudo support in SSSD, was to ensure "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"that running sudo with SSSD as the data source provides the same user "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"experience and is as fast as sudo but keeps providing the most current set "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"of rules as possible. To satisfy these requirements, SSSD uses three kinds "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"of updates. They are referred to as full refresh, smart refresh and rules "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"The <emphasis>smart refresh</emphasis> periodically downloads rules that are "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"new or were modified after the last update. Its primary goal is to keep the "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"database growing by fetching only small increments that do not generate "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"large amounts of network traffic."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"The <emphasis>full refresh</emphasis> simply deletes all sudo rules stored "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"in the cache and replaces them with all rules that are stored on the server. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"This is used to keep the cache consistent by removing every rule which was "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"deleted from the server. However, full refresh may produce a lot of traffic "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"and thus it should be run only occasionally depending on the size and "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"stability of the sudo rules."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"The <emphasis>rules refresh</emphasis> ensures that we do not grant the user "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"more permission than defined. It is triggered each time the user runs sudo. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Rules refresh will find all rules that apply to this user, check their "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"expiration time and redownload them if expired. In the case that any of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"these rules are missing on the server, the SSSD will do an out of band full "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"refresh because more rules (that apply to other users) may have been deleted."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"If enabled, SSSD will store only rules that can be applied to this machine. "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"This means rules that contain one of the following values in "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>sudoHost</emphasis> attribute:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "keyword ALL"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "keyword ALL"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "wildcard"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "ワイルドカード"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "netgroup (in the form \"+netgroup\")"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "netgroup (\"+netgroup\" の形式)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "hostname or fully qualified domain name of this machine"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "このマシンのホスト名または完全修飾ドメイン名"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "one of the IP addresses of this machine"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "このマシンの IP アドレスのどれか"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "one of the IP addresses of the network (in the form \"address/mask\")"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "ネットワークの IP アドレスのどれか (\"address/mask\" 形式)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"There are many configuration options that can be used to adjust the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"behavior. Please refer to \"ldap_sudo_*\" in <citerefentry> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"citerefentry> and \"sudo_*\" in <citerefentry> <refentrytitle>sssd.conf</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "System Security Services Daemon"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "System Security Services Daemon"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sssd</command> <arg choice='opt'> <replaceable>options</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable> </arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sssd</command> <arg choice='opt'> <replaceable>options</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"replaceable> </arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>SSSD</command> provides a set of daemons to manage access to remote "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directories and authentication mechanisms. It provides an NSS and PAM "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"interface toward the system and a pluggable backend system to connect to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"multiple different account sources as well as D-Bus interface. It is also "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the basis to provide client auditing and policy services for projects like "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"FreeIPA. It provides a more robust database to store local users as well as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"extended user data."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>SSSD</command> はリモートディレクトリーへのアクセスと認証メカニズム"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"を管理するための一組のデーモンを提供します。システムへの NSS と PAM インター"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"フェースを提供します。また、D-Bus インターフェースのように複数の異なるアカウ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ントソースに接続するための取り外し可能なバックエンドシステムを提供します。ク"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ライアント監査、およびFreeIPA のようなプロジェクトに対するポリシーサービスを"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"提供する基礎となります。ローカルユーザーだけでなく拡張ユーザーデータを保存す"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"るためのより強靭なデータベースを提供します。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<emphasis>1</emphasis>: デバッグメッセージに日時を追加します"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<emphasis>0</emphasis>: デバッグメッセージで日時を無効にします"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<option>--debug-microseconds=</option><replaceable>mode</replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>1</emphasis>: デバッグメッセージにミリ秒をタイムスタンプに追加しま"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<emphasis>0</emphasis>: Disable microseconds in timestamp"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "<emphasis>0</emphasis>: 日時でマイクロ秒を無効にします"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-f</option>,<option>--debug-to-files</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<option>-f</option>,<option>--debug-to-files</option>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Send the debug output to files instead of stderr. By default, the log files "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are stored in <filename>/var/log/sssd</filename> and there are separate log "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"files for every SSSD service and domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"デバッグ出力を標準エラーの代わりにファイルに送信します。初期状態で、ログファ"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"イルは <filename>/var/log/sssd</filename> に保存され、すべての SSSD サービス"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"とドメインに対して別々のログファイルがあります。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-D</option>,<option>--daemon</option>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "<option>-D</option>,<option>--daemon</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Become a daemon after starting up."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "起動後にデーモンになります。"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-i</option>,<option>--interactive</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "<option>-i</option>,<option>--interactive</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Run in the foreground, don't become a daemon."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "フォアグラウンドで実行して、デーモンになりません。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>-c</option>,<option>--config</option>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "<option>-c</option>,<option>--config</option>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specify a non-default config file. The default is <filename>/etc/sssd/sssd."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"conf</filename>. For reference on the config file syntax and options, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"consult the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> manual page."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"非標準の設定ファイルを指定します。初期値は <filename>/etc/sssd/sssd.conf</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"filename> です。設定ファイルの構文とオプションは <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> マニュアルページを参照してください。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>--version</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "<option>--version</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Print version number and exit."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "バージョン番号を表示して終了します。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Signals"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "シグナル"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Informs the SSSD to gracefully terminate all of its child processes and then "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"shut down the monitor."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD にすべての子プロセスを穏やかに停止するよう通知して、モニターをシャットダ"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SIGHUP"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "SIGHUP"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Tells the SSSD to stop writing to its current debug file descriptors and to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"close and reopen them. This is meant to facilitate log rolling with programs "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"like logrotate."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD が現在のデバッグファイルディスクリプターに書き込むことを止めて、それらを"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"閉じてから開きなおすよう指示します。これは logrotate のようなプログラムを用い"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"てログローテーションを促進することを意味します。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "SIGUSR1"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "SIGUSR1"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Tells the SSSD to simulate offline operation for the duration of the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>offline_timeout</quote> parameter. This is useful for testing. The "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"signal can be sent to either the sssd process or any sssd_be process "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "SIGUSR2"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "SIGUSR2"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Tells the SSSD to go online immediately. This is useful for testing. The "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"signal can be sent to either the sssd process or any sssd_be process "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"applications will not use the fast in memory cache."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "sss_obfuscate"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "sss_obfuscate"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "obfuscate a clear text password"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "平文パスワードをわかりにくくする"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable></arg>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable></arg>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<command>sss_obfuscate</command> converts a given password into human-"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"unreadable format and places it into appropriate domain section of the SSSD "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<command>sss_obfuscate</command> は、与えられたパスワードを人間が読みにくい形"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"式に変換して、SSSD 設定ファイルの適切なドメインセクションに置きます。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The cleartext password is read from standard input or entered "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"interactively. The obfuscated password is put into "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap_default_authtok</quote> parameter of a given SSSD domain and the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap_default_authtok_type</quote> parameter is set to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>obfuscated_password</quote>. Refer to <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more details on these parameters."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"平文のパスワードは、標準入力から読み込まれます、または対話的に入力されます。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"解読しにくくされたパスワードが指定された SSSD ドメインの "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>ldap_default_authtok</quote> パラメータに置かれます。また "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap_default_authtok_type</quote> パラメーターが "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>obfuscated_password</quote> に設定されます。これらのパラメーターの詳細"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"は <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> を参照してください。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Please note that obfuscating the password provides <emphasis>no real "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"security benefit</emphasis> as it is still possible for an attacker to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"reverse-engineer the password back. Using better authentication mechanisms "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"パスワードをわかりにくくすることは、攻撃者がパスワードをリバースエンジニアリ"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ングできるので <emphasis>実際にセキュリティの便益</emphasis> は提供されませ"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"ん。クライアントサイド証明書や GSSAPI のようなより良い認証機構を使用すること"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"を <emphasis>強く</emphasis> 推奨します。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>-s</option>,<option>--stdin</option>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "<option>-s</option>,<option>--stdin</option>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The password to obfuscate will be read from standard input."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "解読しにくくするパスワードが標準入力から読み込まれます。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:70
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The SSSD domain to use the password in. The default name is <quote>default</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"パスワードに使用する SSSD ドメインです。名前の初期値は <quote>default</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Read the config file specified by the positional parameter."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "位置パラメーターにより指定された設定ファイルを読み込みます。"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: <filename>/etc/sssd/sssd.conf</filename>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr "初期値: <filename>/etc/sssd/sssd.conf</filename>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sss_override"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "create local overrides of user and group attributes"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>sss_override</command> enables to create a client-side view and "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"allows to change selected values of specific user and groups. This change "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"takes effect only on local machine."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Overrides data are stored in the SSSD cache. If the cache is deleted, all "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"local overrides are lost. Please note that after the first override is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"created using any of the following <emphasis>user-add</emphasis>, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> or "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<emphasis>group-import</emphasis> command. SSSD needs to be restarted to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"take effect. <emphasis>sss_override</emphasis> prints message when a "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"restart is required."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "AVAILABLE COMMANDS"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Argument <emphasis>NAME</emphasis> is the name of original object in all "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"commands. It is not possible to override <emphasis>uid</emphasis> or "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<emphasis>gid</emphasis> to 0."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"optional> <optional><option>-g,--gid</option> GID</optional> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<optional><option>-h,--home</option> HOME</optional> <optional><option>-s,--"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"shell</option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"CERTIFICATE</optional>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Override attributes of an user. Please be aware that calling this command "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"will replace any previous override for the (NAMEd) user."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>user-del</option> <emphasis>NAME</emphasis>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Remove user overrides. However be aware that overridden attributes might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"returned from memory cache. Please see SSSD option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is set, only users from the domain are listed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>user-show</option> <emphasis>NAME</emphasis>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Show user overrides."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>user-import</option> <emphasis>FILE</emphasis>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Import user overrides from <emphasis>FILE</emphasis>. Data format is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"similar to standard passwd file. The format is:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"where original_name is original name of the user whose attributes should be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"overridden. The rest of fields correspond to new values. You can omit a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"value simply by leaving corresponding field empty."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ckent:superman::::::"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>user-export</option> <emphasis>FILE</emphasis>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Export all overridden attributes and store them in <emphasis>FILE</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"emphasis>. See <emphasis>user-import</emphasis> for data format."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Override attributes of a group. Please be aware that calling this command "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"will replace any previous override for the (NAMEd) group."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "<option>group-del</option> <emphasis>NAME</emphasis>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Remove group overrides. However be aware that overridden attributes might be "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"returned from memory cache. Please see SSSD option "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"List all groups with set overrides. If <emphasis>DOMAIN</emphasis> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"parameter is set, only groups from the domain are listed."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "<option>group-show</option> <emphasis>NAME</emphasis>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Show group overrides."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "<option>group-import</option> <emphasis>FILE</emphasis>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Import group overrides from <emphasis>FILE</emphasis>. Data format is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"similar to standard group file. The format is:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "original_name:name:gid"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"where original_name is original name of the group whose attributes should be "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"overridden. The rest of fields correspond to new values. You can omit a "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"value simply by leaving corresponding field empty."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "admins:administrators:"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Domain Users:Users:501"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "<option>group-export</option> <emphasis>FILE</emphasis>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Export all overridden attributes and store them in <emphasis>FILE</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"emphasis>. See <emphasis>group-import</emphasis> for data format."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "COMMON OPTIONS"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Those options are available with all commands."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>--debug</option> <replaceable>LEVEL</replaceable>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_useradd.8.xml:10 sss_useradd.8.xml:15
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sss_useradd"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "sss_useradd"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "create a new user"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr "新しいユーザーを作成する"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_useradd</command> <arg choice='opt'> <replaceable>options</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>sss_useradd</command> <arg choice='opt'> <replaceable>options</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<command>sss_useradd</command> creates a new user account using the values "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"specified on the command line plus the default values from the system."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_useradd</command> は、コマンドラインにおいて指定された値とシステ"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ムの初期値を使用して、新しいユーザーを作成します。"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Set the UID of the user to the value of <replaceable>UID</replaceable>. If "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"not given, it is chosen automatically."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ユーザーの UID を <replaceable>UID</replaceable> の値を設定します。与えられな"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"いと、自動的に選択されます。"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sss_useradd.8.xml:55 sss_usermod.8.xml:43 sss_seed.8.xml:100
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_useradd.8.xml:60 sss_usermod.8.xml:48 sss_seed.8.xml:105
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Any text string describing the user. Often used as the field for the user's "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ユーザーを説明している任意のテキスト文字列です。しばしばユーザーの完全名の項"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: sss_useradd.8.xml:67 sss_usermod.8.xml:55 sss_seed.8.xml:112
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The home directory of the user account. The default is to append the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<replaceable>LOGIN</replaceable> name to <filename>/home</filename> and use "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"that as the home directory. The base that is prepended before "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<replaceable>LOGIN</replaceable> is tunable with <quote>user_defaults/"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"baseDirectory</quote> setting in sssd.conf."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ユーザーアカウントのホームディレクトリーです。初期値は <filename>/home</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"filename> に <replaceable>LOGIN</replaceable> の名前を追加して、ホームディレ"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"クトリーとして使用します。 <replaceable>LOGIN</replaceable> の前につけるベー"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"スは sssd.conf において <quote>user_defaults/baseDirectory</quote> 設定で変更"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sss_useradd.8.xml:82 sss_usermod.8.xml:66 sss_seed.8.xml:124
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The user's login shell. The default is currently <filename>/bin/bash</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"filename>. The default can be changed with <quote>user_defaults/"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"defaultShell</quote> setting in sssd.conf."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ユーザーのログインシェルです。初期値は現在 <filename>/bin/bash</filename> で"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"す。初期値は sssd.conf において <quote>user_defaults/defaultShell</quote> で"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<option>-G</option>,<option>--groups</option> <replaceable>GROUPS</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"replaceable>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<option>-G</option>,<option>--groups</option> <replaceable>GROUPS</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"replaceable>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "A list of existing groups this user is also a member of."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr "このユーザーがメンバーである既存のユーザーの一覧です。"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>-m</option>,<option>--create-home</option>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "<option>-m</option>,<option>--create-home</option>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Create the user's home directory if it does not exist. The files and "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"directories contained in the skeleton directory (which can be defined with "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"the -k option or in the config file) will be copied to the home directory."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"ユーザーのホームディレクトリーが存在しなければ、それを作成します。(-k オプ"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"ションまたは設定ファイルで定義できる)スケルトンディレクトリーにあるファイル"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"とディレクトリーがホームディレクトリーにコピーされます。"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "<option>-M</option>,<option>--no-create-home</option>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "<option>-M</option>,<option>--no-create-home</option>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Do not create the user's home directory. Overrides configuration settings."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr "ユーザーのホームディレクトリーを作成しません。設定を上書きします。"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<option>-k</option>,<option>--skel</option> <replaceable>SKELDIR</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"replaceable>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<option>-k</option>,<option>--skel</option> <replaceable>SKELDIR</"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"replaceable>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"The skeleton directory, which contains files and directories to be copied in "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"the user's home directory, when the home directory is created by "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"<command>sss_useradd</command>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"スケルトンディレクトリーです。ホームディレクトリーが <command>sss_useradd</"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"command> により作成されるとき、ユーザーのホームディレクトリーにコピーされる"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ファイルとディレクトリーを含みます。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Special files (block devices, character devices, named pipes and unix "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"sockets) will not be copied."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"特殊ファイル (ブロックデバイス、キャラクターデバイス、名前付きパイプおよび "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"UNIX ソケット) はコピーされません。"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"This option is only valid if the <option>-m</option> (or <option>--create-"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"home</option>) option is specified, or creation of home directories is set "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"to TRUE in the configuration."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<option>-m</option> (または <option>--create-home</option>) オプションが指定"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"されたとき、またはホームディレクトリーの作成が設定において TRUE に設定されて"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"いる場合のみ、このオプションが有効です。"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<option>-Z</option>,<option>--selinux-user</option> "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<replaceable>SELINUX_USER</replaceable>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<option>-Z</option>,<option>--selinux-user</option> "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<replaceable>SELINUX_USER</replaceable>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"The SELinux user for the user's login. If not specified, the system default "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"will be used."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"ユーザーがログインする際の SELinux ユーザーです。未指定の場合、システムの初期"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "sssd-krb5"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "sssd-krb5"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "SSSD Kerberos provider"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"This manual page describes the configuration of the Kerberos 5 "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"authentication backend for <citerefentry> <refentrytitle>sssd</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. For a detailed "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"syntax reference, please refer to the <quote>FILE FORMAT</quote> section of "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manvolnum> </citerefentry> manual page."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"このマニュアルは <citerefentry> <refentrytitle>sssd</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> に対する Kerberos 5 認証バックエンド"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"の設定を説明しています。詳細な構文の参考資料は、<citerefentry> "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"citerefentry> マニュアルページの <quote>ファイル形式</quote> セクションを参照"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"The Kerberos 5 authentication backend contains auth and chpass providers. It "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"must be paired with an identity provider in order to function properly (for "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"example, id_provider = ldap). Some information required by the Kerberos 5 "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"authentication backend must be provided by the identity provider, such as "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the user's Kerberos Principal Name (UPN). The configuration of the identity "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"provider should have an entry to specify the UPN. Please refer to the man "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"page for the applicable identity provider for details on how to configure "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Kerberos 5 認証バックエンドは認証プロバイダーおよびパスワード変更プロバイダー"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"を含みます。正しく機能するためには識別プロダイバーと組み合わせて使用する必要"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"があります (たとえば、id_provider = ldap)。Kerberos 5 認証バックエンドにより"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"必要とされるいくつかの情報は、ユーザーの Kerberos プリンシパル名 (UPN) のよう"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"な、識別プロバイダーにより提供される必要があります。識別プロバイダーの設定は "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"UPN を指定するためのエントリーがある必要があります。これを設定する方法に関す"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"る詳細は適用可能な識別プロバイダーのマニュアルページを参照してください。"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"This backend also provides access control based on the .k5login file in the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"home directory of the user. See <citerefentry> <refentrytitle>.k5login</"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry> for more details. "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Please note that an empty .k5login file will deny all access to this user. "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"To activate this feature, use 'access_provider = krb5' in your SSSD "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"configuration."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"このバックエンドは、ユーザーのホームディレクトリーにある .k5login ファイルに"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"基づいたアクセス制御を提供します。詳細は <citerefentry> <refentrytitle>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"k5login</refentrytitle><manvolnum>5</manvolnum> </citerefentry> を参照してく"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"ださい。空の .k5login ファイルがあると、このユーザーに対するすべてのアクセス"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"が拒否されます。この機能を有効にするには、SSSD 設定において 'access_provider "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"= krb5' を使用します。"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"In the case where the UPN is not available in the identity backend, "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<command>sssd</command> will construct a UPN using the format "
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozek"<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>."
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:77
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:106
#: sssd-krb5.5.xml:113
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:116
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:122
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:129
#: sssd-krb5.5.xml:135
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:138
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:145
#: sssd-krb5.5.xml:151
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:170
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-krb5.5.xml:173
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:174
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-krb5.5.xml:178
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:179
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-krb5.5.xml:182
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:188
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:194
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:154
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:208
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:216
"stored in the system wide krb5.conf configuration file in the [libdefaults] "
"section. The option name is default_ccache_name. See krb5.conf(5)'s "
"format defined by krb5.conf."
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:225
"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:234
#: sssd-krb5.5.xml:240
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:243
#: sssd-krb5.5.xml:254
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:257
#: sssd-krb5.5.xml:272
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:275
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:279
msgid "Default: /etc/krb5.keytab"
msgstr "初期値: /etc/krb5.keytab"
#: sssd-krb5.5.xml:285
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:288
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:293
#: sssd-krb5.5.xml:306
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:309
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:335
msgid "Default: not set, i.e. the TGT is not renewable"
#: sssd-krb5.5.xml:341
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:344
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:360
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:364
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:369
"Default: not set, i.e. the default ticket lifetime configured on the KDC."
#: sssd-krb5.5.xml:376
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:379
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:406
#: sssd-krb5.5.xml:416
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:419
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:424
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:428
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:433
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:438
msgid "Default: not set, i.e. FAST is not used."
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:441
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:444
#: sssd-krb5.5.xml:453
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:456
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:465
#: sssd-krb5.5.xml:505
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:508
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:514
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:517
#: sssd-krb5.5.xml:526
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:529
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-krb5.5.xml:541
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-krb5.5.xml:546
#: sssd-krb5.5.xml:65
"must be used. See the <citerefentry> <refentrytitle>sssd.conf</"
"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
#: sssd-krb5.5.xml:572
#: sssd-krb5.5.xml:580
"[domain/FOO]\n"
"krb5_realm = EXAMPLE.COM\n"
#: sss_groupadd.8.xml:16
#: sss_groupadd.8.xml:21
#: sss_groupadd.8.xml:32
#: sss_groupadd.8.xml:48
#: sss_userdel.8.xml:16
#: sss_userdel.8.xml:21
#: sss_userdel.8.xml:32
#: sss_userdel.8.xml:44
#: sss_userdel.8.xml:48
#: sss_userdel.8.xml:56
#: sss_userdel.8.xml:60
#: sss_userdel.8.xml:68
#: sss_userdel.8.xml:72
#: sss_userdel.8.xml:80
#: sss_userdel.8.xml:84
#: sss_groupdel.8.xml:16
#: sss_groupdel.8.xml:21
#: sss_groupdel.8.xml:32
#: sss_groupshow.8.xml:16
#: sss_groupshow.8.xml:21
#: sss_groupshow.8.xml:32
#: sss_groupshow.8.xml:43
#: sss_groupshow.8.xml:47
#: sss_usermod.8.xml:16
#: sss_usermod.8.xml:21
#: sss_usermod.8.xml:32
#: sss_usermod.8.xml:60
#: sss_usermod.8.xml:71
#: sss_usermod.8.xml:82
#: sss_usermod.8.xml:96
#: sss_usermod.8.xml:103
#: sss_usermod.8.xml:107
#: sss_usermod.8.xml:114
#: sss_usermod.8.xml:118
#: sss_usermod.8.xml:129
#: sss_usermod.8.xml:135
#: sss_usermod.8.xml:140
msgid "Add an attribute/value pair. The format is attrname=value."
#: sss_usermod.8.xml:147
#: sss_usermod.8.xml:152
"Set an attribute to a name/value pair. The format is attrname=value. For "
#: sss_usermod.8.xml:160
#: sss_usermod.8.xml:165
msgid "Delete an attribute/value pair. The format is attrname=value."
#: sss_cache.8.xml:16
#: sss_cache.8.xml:21
#: sss_cache.8.xml:31
#: sss_cache.8.xml:43
#: sss_cache.8.xml:47
#: sss_cache.8.xml:53
#: sss_cache.8.xml:58
#: sss_cache.8.xml:64
#: sss_cache.8.xml:68
#: sss_cache.8.xml:75
#: sss_cache.8.xml:80
#: sss_cache.8.xml:86
#: sss_cache.8.xml:90
#: sss_cache.8.xml:97
#: sss_cache.8.xml:102
#: sss_cache.8.xml:108
#: sss_cache.8.xml:112
#: sss_cache.8.xml:119
#: sss_cache.8.xml:124
#: sss_cache.8.xml:130
#: sss_cache.8.xml:134
#: sss_cache.8.xml:141
#: sss_cache.8.xml:146
#: sss_cache.8.xml:152
#: sss_cache.8.xml:156
#: sss_cache.8.xml:163
#: sss_cache.8.xml:168
#: sss_cache.8.xml:174
#: sss_cache.8.xml:178
#: sss_cache.8.xml:186
#: sss_cache.8.xml:191
#: sss_cache.8.xml:197
#: sss_cache.8.xml:201
#: sss_cache.8.xml:209
#: sss_cache.8.xml:214
#: sss_debuglevel.8.xml:16
#: sss_debuglevel.8.xml:21
#: sss_debuglevel.8.xml:32
#: sss_seed.8.xml:16
#: sss_seed.8.xml:21
#: sss_seed.8.xml:33
#: sss_seed.8.xml:46
#: sss_seed.8.xml:51
"sssd.conf. The <replaceable>DOMAIN</replaceable> option must be provided. "
#: sss_seed.8.xml:63
#: sss_seed.8.xml:68
#: sss_seed.8.xml:81
#: sss_seed.8.xml:93
#: sss_seed.8.xml:117
#: sss_seed.8.xml:129
#: sss_seed.8.xml:140
#: sss_seed.8.xml:148
#: sss_seed.8.xml:153
#: sss_seed.8.xml:165
#: sssd-ifp.5.xml:17
#: sssd-ifp.5.xml:23
"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
#: sssd-ifp.5.xml:36
#: sssd-ifp.5.xml:46
#: sssd-ifp.5.xml:53
#: sssd-ifp.5.xml:59
#: sssd-ifp.5.xml:63
#: sssd-ifp.5.xml:77
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:91
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-ifp.5.xml:92
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:95
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-ifp.5.xml:96
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:99
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-ifp.5.xml:100
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:103
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-ifp.5.xml:104
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:107
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-ifp.5.xml:111
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-ifp.5.xml:112
#: sssd-ifp.5.xml:81
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-ifp.5.xml:125
#: sssd-ifp.5.xml:117
#: sssd-ifp.5.xml:129
#: sssd-ifp.5.xml:139
#: sssd-ifp.5.xml:144
#: sss_rpcidmapd.5.xml:8
"<productname>sss rpc.idmapd plugin</productname> <author> <firstname>Noam</"
#: sss_rpcidmapd.5.xml:33
msgid "sss plugin configuration directives for rpc.idmapd"
#: sss_rpcidmapd.5.xml:37
#: sss_rpcidmapd.5.xml:39
"conf</emphasis>. See <citerefentry> <refentrytitle>idmapd.conf</"
#: sss_rpcidmapd.5.xml:49
#: sss_rpcidmapd.5.xml:51
#: sss_rpcidmapd.5.xml:53
"In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> "
#: sss_rpcidmapd.5.xml:59
#: sss_rpcidmapd.5.xml:61
#: sss_rpcidmapd.5.xml:67
#: sss_rpcidmapd.5.xml:69
#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
#: sss_rpcidmapd.5.xml:72
#: sss_rpcidmapd.5.xml:85
#: sss_rpcidmapd.5.xml:87
#: sss_rpcidmapd.5.xml:91
#: sss_rpcidmapd.5.xml:103
"# Solaris/Illumos/AIX use \"localdomain\" as default!\n"
#: sss_rpcidmapd.5.xml:100
"The following example shows a minimal idmapd.conf which makes use of the sss "
#: sss_rpcidmapd.5.xml:122
"citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> "
" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n"
"manvolnum></citerefentry> for more information) <filename>/var/lib/sss/"
"pubconf/known_hosts</filename> and establishes the connection to the host."
"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n"
"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n"
"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n"
"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n"
#: idmap_sss.8.xml:16
#: idmap_sss.8.xml:22
"The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and SIDs. "
#: idmap_sss.8.xml:29
#: idmap_sss.8.xml:33
#: idmap_sss.8.xml:35
#: idmap_sss.8.xml:45
#: idmap_sss.8.xml:50
#: sssctl.8.xml:16
#: sssctl.8.xml:21
#: sssctl.8.xml:32
#: sssctl.8.xml:43
#: sssd-files.5.xml:17
#: sssd-files.5.xml:23
"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
#: sssd-files.5.xml:36
#: sssd-files.5.xml:59
#: sssd-files.5.xml:73
#: sssd-files.5.xml:79
"[domain/files]\n"
#: sssd-secrets.5.xml:17
#: sssd-secrets.5.xml:23
"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
#: sssd-secrets.5.xml:36
#: sssd-secrets.5.xml:45
"The <ulink url=\"https://github.com/latchset/custodia\">custodia</ulink> "
#: sssd-secrets.5.xml:55
#: sssd-secrets.5.xml:69
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:70
#: sssd-secrets.5.xml:73
#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:75
#: sssd-secrets.5.xml:61
#: sssd-secrets.5.xml:89
#: sssd-secrets.5.xml:91
"run/secrets.socket</filename>."
#: sssd-secrets.5.xml:110
"systemctl start sssd-secrets.socket\n"
"systemctl enable sssd-secrets.socket\n"
"systemctl enable sssd-secrets.service\n"
#: sssd-secrets.5.xml:95
"The systemd socket unit is called <quote>sssd-secrets.socket</quote> and the "
"corresponding service file is called <quote>sssd-secrets.service</quote>. In "
#: sssd-secrets.5.xml:122
"to the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
#: sssd-secrets.5.xml:132
"section and an optional per-user <quote>[secrets/users/$uid]</quote> section "
"in <filename>sssd.conf</filename>. Please note that some options, notably as "
#: sssd-secrets.5.xml:141
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-secrets.5.xml:157
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:160
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
#: sssd-secrets.5.xml:168
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:171
#: sssd-secrets.5.xml:144
"responder can configure a per-user subsections (e.g. <quote>[secrets/"
#: sssd-secrets.5.xml:180
#: sssd-secrets.5.xml:186
#: sssd-secrets.5.xml:192
#: sssd-secrets.5.xml:195
#: sssd-secrets.5.xml:199
#: sssd-secrets.5.xml:204
#: sssd-secrets.5.xml:207
#: sssd-secrets.5.xml:211
#: sssd-secrets.5.xml:216
#: sssd-secrets.5.xml:219
#: sssd-secrets.5.xml:223
#: sssd-secrets.5.xml:228
#: sssd-secrets.5.xml:231
#: sssd-secrets.5.xml:235
#: sssd-secrets.5.xml:244
"[secrets/secrets]\n"
"[secrets/kcm]\n"
#: sssd-secrets.5.xml:241
#: sssd-secrets.5.xml:252
#: sssd-secrets.5.xml:257
#: sssd-secrets.5.xml:260
#: sssd-secrets.5.xml:267
#: sssd-secrets.5.xml:270
msgid "Example: http://localhost:8080"
#: sssd-secrets.5.xml:275
#: sssd-secrets.5.xml:278
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><term>
#: sssd-secrets.5.xml:283
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:286
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><term>
#: sssd-secrets.5.xml:293
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><listitem><para>
#: sssd-secrets.5.xml:296
#: sssd-secrets.5.xml:307
#: sssd-secrets.5.xml:310
#: sssd-secrets.5.xml:315
#: sssd-secrets.5.xml:320
#: sssd-secrets.5.xml:323
#: sssd-secrets.5.xml:327
#: sssd-secrets.5.xml:332
#: sssd-secrets.5.xml:335
#: sssd-secrets.5.xml:344
#: sssd-secrets.5.xml:347
#: sssd-secrets.5.xml:356
#: sssd-secrets.5.xml:359
#: sssd-secrets.5.xml:369
#: sssd-secrets.5.xml:372
#: sssd-secrets.5.xml:382
#: sssd-secrets.5.xml:385
#: sssd-secrets.5.xml:395
#: sssd-secrets.5.xml:398
#: sssd-secrets.5.xml:409
#: sssd-secrets.5.xml:412
#: sssd-secrets.5.xml:422
#: sssd-secrets.5.xml:424
"the Content Type header to <quote>application/json</quote>. In addition, the "
"local provider also supports Content Type set to <quote>application/octet-"
"header to <quote>application/octet-stream</quote> are base64-encoded when "
#: sssd-secrets.5.xml:441
#: sssd-secrets.5.xml:444
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:450
"curl -H \"Content-Type: application/json\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XGET http://localhost/secrets/\n"
#: sssd-secrets.5.xml:458
#: sssd-secrets.5.xml:461
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:468
"curl -H \"Content-Type: application/json\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XGET http://localhost/secrets/foo\n"
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:473
"curl -H \"Content-Type: application/octet-stream\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XGET http://localhost/secrets/bar\n"
#: sssd-secrets.5.xml:466
#: sssd-secrets.5.xml:481
#: sssd-secrets.5.xml:484
"To set a secret using the <quote>application/json</quote> type, send a HTTP "
#: sssd-secrets.5.xml:492
"The <quote>application/json</quote> type just sends the secret as the "
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:501
"curl -H \"Content-Type: application/json\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XPUT http://localhost/secrets/foo \\\n"
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:507
"curl -H \"Content-Type: application/octet-stream\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XPUT http://localhost/secrets/bar \\\n"
#: sssd-secrets.5.xml:496
#: sssd-secrets.5.xml:516
#: sssd-secrets.5.xml:519
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:529
"curl -H \"Content-Type: application/json\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XPOST http://localhost/secrets/mycontainer/\n"
#: sssd-secrets.5.xml:526
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:538
#: sssd-secrets.5.xml:535
#: sssd-secrets.5.xml:544
#: sssd-secrets.5.xml:547
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
#: sssd-secrets.5.xml:553
"curl -H \"Content-Type: application/json\" \\\n"
" --unix-socket /var/run/secrets.socket \\\n"
" -XDELETE http://localhost/secrets/foo\n"
#: sssd-secrets.5.xml:551
#: sssd-secrets.5.xml:563
#: sssd-secrets.5.xml:565
#: sssd-secrets.5.xml:576
"server_url = http://localhost:8080/\n"
"auditlog = /var/log/custodia.log\n"
"handler = custodia.store.sqlite.SqliteStore\n"
"dburi = /var/lib/custodia.db\n"
"handler = custodia.httpd.authenticators.SimpleHeaderAuth\n"
"handler = custodia.httpd.authorizers.SimplePathAuthz\n"
"handler = custodia.root.Root\n"
#: sssd-secrets.5.xml:570
"into a file (for example, <replaceable>custodia.conf</replaceable>): "
#: sssd-secrets.5.xml:602
#: sssd-secrets.5.xml:606
#: sssd-secrets.5.xml:614
"[secrets/users/123]\n"
"proxy_url = http://localhost:8080/secrets/\n"
#| "<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
"section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
"明しています。詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
"type during their sessions on text terminals. E.g. when users log in on the "
#: sssd-session-recording.5.xml:146
"The following snippet of sssd.conf enables session recording for users "
#: sssd-session-recording.5.xml:151
#: sssd-kcm.8.xml:17
#: sssd-kcm.8.xml:23
#: sssd-kcm.8.xml:31
"(typically used through an application, like e.g., <citerefentry> "
#: sssd-kcm.8.xml:42
#: sssd-kcm.8.xml:47
#: sssd-kcm.8.xml:51
#: sssd-kcm.8.xml:56
#: sssd-kcm.8.xml:61
#: sssd-kcm.8.xml:69
#: sssd-kcm.8.xml:76
#: sssd-kcm.8.xml:86
#: sssd-kcm.8.xml:78
"credential type in <citerefentry> <refentrytitle>krb5.conf</"
#: sssd-kcm.8.xml:91
"the <citerefentry> <refentrytitle>krb5.conf</refentrytitle><manvolnum>5</"
#: sssd-kcm.8.xml:113
"systemctl start sssd-kcm.socket\n"
"systemctl enable sssd-kcm.socket\n"
#: sssd-kcm.8.xml:102
#: sssd-kcm.8.xml:122
#: sssd-kcm.8.xml:131
"systemctl start sssd-secrets.socket\n"
"systemctl enable sssd-secrets.socket\n"
#: sssd-kcm.8.xml:124
#: sssd-kcm.8.xml:141
"section of sssd.conf. For a detailed syntax reference, refer to the "
#: sssd-kcm.8.xml:155
"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
#: sssd-kcm.8.xml:166
#: sssd-kcm.8.xml:169
#: sssd-kcm.8.xml:172
#: sssd-kcm.8.xml:182
"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</"
#: sssd-systemtap.5.xml:17
#: sssd-systemtap.5.xml:23
#| "<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </"
"セマンティックの詳細な説明は <citerefentry> <refentrytitle>sudoers.ldap</"
#: sssd-systemtap.5.xml:32
#: sssd-systemtap.5.xml:40
msgid "Sample SystemTap scripts are provided in /usr/share/sssd/systemtap/"
#: sssd-systemtap.5.xml:46
"Probes and miscellaneous functions are defined in /usr/share/systemtap/"
#: sssd-systemtap.5.xml:57
#: sssd-systemtap.5.xml:64
#: sssd-systemtap.5.xml:67
#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:70
#: sssd-systemtap.5.xml:80
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:84
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:87
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:131
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:97
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:100
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:111
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:114
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:124
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:127
#: sssd-systemtap.5.xml:141
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:145
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:148
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:160
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:163
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:175
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:178
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:182
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:189
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:192
#: sssd-systemtap.5.xml:208
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:212
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:215
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:227
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:230
#: sssd-systemtap.5.xml:246
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:250
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:253
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:293
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:262
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:265
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:274
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:277
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:286
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:289
#: sssd-systemtap.5.xml:302
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:306
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:309
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:312
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
#: sssd-systemtap.5.xml:320
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:323
#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><programlisting>
#: sssd-systemtap.5.xml:326
#: sssd-systemtap.5.xml:339
#: sssd-systemtap.5.xml:346
#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:349
#: sssd-systemtap.5.xml:354
#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:358
#: sssd-systemtap.5.xml:363
#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:366
#: sssd-systemtap.5.xml:371
#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
#: sssd-systemtap.5.xml:374
"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
"詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
#: include/upstream.xml:2
"<productname>SSSD</productname> <orgname>The SSSD upstream - https://pagure."
"io/SSSD/sssd/</orgname>"
#: include/upstream.xml:1
#: include/failover.xml:2
#: include/failover.xml:4
#: include/failover.xml:8
#: include/failover.xml:10
#: include/failover.xml:16
#: include/failover.xml:27
#: include/failover.xml:29
#: include/failover.xml:42
#: include/failover.xml:47
#: include/failover.xml:53
#: include/failover.xml:55
#: include/failover.xml:76
#: include/failover.xml:80
#: include/failover.xml:86
#: include/failover.xml:90
#: include/failover.xml:67
#| "section of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
"in the <citerefentry> <refentrytitle>sssd.conf</refentrytitle><manvolnum>5</"
"す。完全な詳細は <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
#: include/failover.xml:100
#: include/ldap_id_mapping.xml:101
"Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):"
msgstr "最小の設定 (<quote>[domain/DOMAINNAME]</quote> セクションにおいて):"
#: include/ldap_id_mapping.xml:106
#: include/ldap_id_mapping.xml:111
#: include/ldap_id_mapping.xml:117
#: include/ldap_id_mapping.xml:120
#: include/ldap_id_mapping.xml:123
#: include/ldap_id_mapping.xml:127
#: include/ldap_id_mapping.xml:142
#: include/ldap_id_mapping.xml:145
#: include/ldap_id_mapping.xml:149
#: include/ldap_id_mapping.xml:159
#: include/ldap_id_mapping.xml:164
#: include/ldap_id_mapping.xml:167
#: include/ldap_id_mapping.xml:173
#: include/ldap_id_mapping.xml:179
"equal to maximal SID minus minimal SID plus one (e.g. 1108 = 1107 - 0 + 1)."
#: include/ldap_id_mapping.xml:186
#: include/ldap_id_mapping.xml:196
#: include/ldap_id_mapping.xml:199
#: include/ldap_id_mapping.xml:210
#: include/ldap_id_mapping.xml:213
#: include/ldap_id_mapping.xml:221
#: include/ldap_id_mapping.xml:224
#: include/ldap_id_mapping.xml:229
#: include/ldap_id_mapping.xml:234
#: include/ldap_id_mapping.xml:249
#: include/ldap_id_mapping.xml:252
#: include/ldap_id_mapping.xml:256
#: include/ldap_id_mapping.xml:273
#: include/ldap_id_mapping.xml:275
"SSSD supports to look up the names of Well-Known SIDs, i.e. SIDs with a "
"those Well-Known SIDs have no equivalent in a Linux/UNIX environment no "
#: include/ldap_id_mapping.xml:281
#: include/ldap_id_mapping.xml:284
#: include/ldap_id_mapping.xml:285
#: include/ldap_id_mapping.xml:286
#: include/ldap_id_mapping.xml:287
#: include/ldap_id_mapping.xml:288
#: include/ldap_id_mapping.xml:289
#: include/ldap_id_mapping.xml:291
#: include/ldap_id_mapping.xml:295
"names in <filename>sssd.conf</filename>."
#: include/debug_levels.xml:10
#: include/debug_levels.xml:18
"<emphasis> This is an experimental feature, please use https://pagure.io/"
"SSSD/sssd/ to report any issues. </emphasis>"
#: include/local.xml:2
#: include/local.xml:4
#: include/local.xml:9
#: include/seealso.xml:4
"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</"
"functions as specified in section 4.5.1.2 of http://tools.ietf.org/html/"
"any autofs-related changes are made to the sssd.conf, you typically also "