nl.po revision d25fa6f2608d5fe0617ada47f9d426f45deb96ff
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# SOME DESCRIPTIVE TITLE
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# Copyright (C) YEAR Red Hat
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher# This file is distributed under the same license as the sssd-docs package.
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher# Translators:
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek# Wijnand Modderman-Lenstra <accounts-transifex@maze.io>, 2011
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Project-Id-Version: sssd-docs 1.12.90\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Report-Msgid-Bugs-To: sssd-devel@redhat.com\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"POT-Creation-Date: 2016-07-07 19:28+0200\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"PO-Revision-Date: 2014-06-04 02:04-0400\n"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"Last-Translator: jhrozek <jhrozek@redhat.com>\n"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Language-Team: Dutch (http://www.transifex.com/projects/p/sssd/language/"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"nl/)\n"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Language: nl\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"MIME-Version: 1.0\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Content-Type: text/plain; charset=UTF-8\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Content-Transfer-Encoding: 8bit\n"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Plural-Forms: nplurals=2; plural=(n != 1);\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"X-Generator: Zanata 3.8.4\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:5 sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sssd-ipa.5.xml:5
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd.8.xml:5 sss_obfuscate.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:5 sss_useradd.8.xml:5 sssd-krb5.5.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupadd.8.xml:5 sss_userdel.8.xml:5 sss_groupdel.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupshow.8.xml:5 sss_usermod.8.xml:5 sss_cache.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_debuglevel.8.xml:5 sss_seed.8.xml:5 sssd-ifp.5.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_rpcidmapd.5.xml:5 sss_ssh_authorizedkeys.1.xml:5
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:5 idmap_sss.8.xml:5 sssctl.8.xml:5
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SSSD Manual pages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SSSD handleiding"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:10 sss_groupmod.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_groupmod"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "sss_groupmod"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:11 pam_sss.8.xml:14 sssd_krb5_locator_plugin.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd.8.xml:11 sss_obfuscate.8.xml:11 sss_override.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_useradd.8.xml:11 sss_groupadd.8.xml:11 sss_userdel.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupdel.8.xml:11 sss_groupshow.8.xml:11 sss_usermod.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_cache.8.xml:11 sss_debuglevel.8.xml:11 sss_seed.8.xml:11
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: idmap_sss.8.xml:11 sssctl.8.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "8"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "8"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "modify a group"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "muteer een groep"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>opties</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROEP</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_groupmod.8.xml:30 sssd-ldap.5.xml:21 pam_sss.8.xml:56
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:20 sssd-simple.5.xml:22 sssd-ipa.5.xml:21
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ad.5.xml:21 sssd-sudo.5.xml:21 sssd.8.xml:29 sss_obfuscate.8.xml:30
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:30 sss_useradd.8.xml:30 sssd-krb5.5.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupadd.8.xml:30 sss_userdel.8.xml:30 sss_groupdel.8.xml:30
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupshow.8.xml:30 sss_usermod.8.xml:30 sss_cache.8.xml:29
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_debuglevel.8.xml:30 sss_seed.8.xml:31 sssd-ifp.5.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:30 sss_ssh_knownhostsproxy.1.xml:31
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: idmap_sss.8.xml:20 sssctl.8.xml:30
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "DESCRIPTION"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "OMSCHRIJVING"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupmod</command> modifies the group to reflect the changes "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"that are specified on the command line."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupmod</command> muteert de groep en maakt de aanpassingen "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"die via de opdrachtregel ingegeven zijn."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_groupmod.8.xml:39 pam_sss.8.xml:63 sssd.8.xml:42 sss_obfuscate.8.xml:58
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:39 sss_groupadd.8.xml:39 sss_userdel.8.xml:39
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:39 sss_groupshow.8.xml:39 sss_usermod.8.xml:39
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_cache.8.xml:38 sss_debuglevel.8.xml:38 sss_seed.8.xml:42
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:66 sss_ssh_knownhostsproxy.1.xml:62
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "OPTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "OPTIES"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:43 sss_usermod.8.xml:77
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROEPEN</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:48
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Append this group to groups specified by the <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"a comma separated list of group names."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Voeg deze groep toe aan de groepen opgegeven met de <replaceable>GROEPEN</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter. De <replaceable>GROEPEN</replaceable> parameter is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"een kommagescheiden lijst van groepnamen."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:57 sss_usermod.8.xml:91
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROEPEN</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupmod.8.xml:62
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Remove this group from groups specified by the <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Verwijder deze groep uit de groepen opgegeven in de <replaceable>GROEPEN</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:10 sssd.conf.5.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd.conf"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "sssd.conf"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:11 sssd-ldap.5.xml:11 sssd-simple.5.xml:11
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ipa.5.xml:11 sssd-ad.5.xml:11 sssd-sudo.5.xml:11 sssd-krb5.5.xml:11
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd-ifp.5.xml:11 sss_rpcidmapd.5.xml:27
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "5"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "5"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refmeta><refmiscinfo>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:12 sssd-ldap.5.xml:12 sssd-simple.5.xml:12
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ipa.5.xml:12 sssd-ad.5.xml:12 sssd-sudo.5.xml:12 sssd-krb5.5.xml:12
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd-ifp.5.xml:12 sss_rpcidmapd.5.xml:28
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "File Formats and Conventions"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Bestandsformaten en conventies"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd.conf.5.xml:17
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "the configuration file for SSSD"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "het configuratiebestand voor SSSD"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FILE FORMAT"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "BESTANDSFORMAAT"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:29
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>[section]</replaceable>\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher" "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:24
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The file has an ini-style syntax and consists of sections and parameters. A "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"section begins with the name of the section in square brackets and continues "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"until the next section begins. An example of section with single and multi-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Het bestand heeft een ini-stijl syntaxis en bestaat uit secties en "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameters. Een sectie begint met de naam van de sectie in rechte haken en "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"gaat verder totdat de volgende sectie begint. Een voorbeeld van een sectie "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"met een enkele en een meervoudige parameter: <placeholder type="
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:36
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The data types used are string (no quotes needed), integer and bool (with "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"values of <quote>TRUE/FALSE</quote>)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"De datatypes gebruikt zijn tekst (geen quotes vereisd), numeriek en "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"booleaans (met de waardes <quote>TRUE/FALSE</quote>)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.conf.5.xml:41
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A line comment starts with a hash sign (<quote>#</quote>) or a semicolon "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"(<quote>;</quote>). Inline comments are not supported."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:47
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"All sections can have an optional <replaceable>description</replaceable> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameter. Its function is only as a label for the section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Alle secties kunnen een optionele <replaceable>description</replaceable> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parameter bevatten. Dit fungeert slechts als label voor de sectie."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:53
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<filename>sssd.conf</filename> must be a regular file, owned by root and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"only root may read from or write to the file."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<filename>sssd.conf</filename> moet een standaardbestand zijn, de eigenaar "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"moet root zijn en alleen root mag hem lezen en schrijven."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:59
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:62
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The configuration file <filename>sssd.conf</filename> will include "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"configuration snippets using the include directory <filename>conf.d</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"filename>. This feature is available if SSSD was compiled with libini "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"version 1.3.0 or later."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:69
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Any file placed in <filename>conf.d</filename> that ends in "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<quote><filename>.conf</filename></quote> and does not begin with a dot "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"to configure SSSD."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:77
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The configuration snippets from <filename>conf.d</filename> have higher "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"priority than <filename>sssd.conf</filename> and will override "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<filename>sssd.conf</filename> when conflicts occur. If several snippets are "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"present in <filename>conf.d</filename>, then they are included in "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"alphabetical order (based on locale). Files included later have higher "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"priority. Numerical prefixes (<filename>01_snippet.conf</filename>, "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<filename>02_snippet.conf</filename> etc.) can help visualize the priority "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"(higher number means higher priority)."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:91
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The snippet files require the same owner and permissions as <filename>sssd."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"conf</filename>. Which are by default root:root and 0600."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:98
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "GENERAL OPTIONS"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:100
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Following options are usable in more than one configuration sections."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:104
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Options usable in all sections"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:108
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_level (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "debug_level (numeriek)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:112
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "debug_level (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "debug (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "debug_level (numeriek)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:115
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for <replaceable>debug_level</replaceable> as a convenience feature. If both "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are specified, the value of <replaceable>debug_level</replaceable> will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"used."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:125
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_timestamps (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "debug_timestamps (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:128
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Add a timestamp to the debug messages. If journald is enabled for SSSD "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"debug logging this option is ignored."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:133 sssd.conf.5.xml:711 sssd.conf.5.xml:1246
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1665 sssd-ldap.5.xml:1762 sssd-ldap.5.xml:1824
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2381 sssd-ldap.5.xml:2446 sssd-ldap.5.xml:2464
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:405 sssd-ipa.5.xml:440 sssd-ad.5.xml:174 sssd-ad.5.xml:272
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:809 sssd-ad.5.xml:928 sssd-krb5.5.xml:499
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: true"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "Standaard: true"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:138
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_microseconds (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:141
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Add microseconds to the timestamp in debug messages. If journald is enabled "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"for SSSD debug logging this option is ignored."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:146 sssd.conf.5.xml:1200 sssd.conf.5.xml:2495
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:692 sssd-ldap.5.xml:1539 sssd-ldap.5.xml:1558
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1734 sssd-ldap.5.xml:2151 sssd-ipa.5.xml:139
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:211 sssd-ipa.5.xml:542 sssd-krb5.5.xml:266
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:300 sssd-krb5.5.xml:471
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: false"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:106 sssd.conf.5.xml:157 sssd-ldap.5.xml:2189
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<placeholder type=\"variablelist\" id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:155
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Options usable in SERVICE and DOMAIN sections"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:159
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:162
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Timeout in seconds between heartbeats for this service. This is used to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ensure that the process is alive and capable of answering requests."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:167 sssd.conf.5.xml:1164 sssd-ldap.5.xml:1410
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:264
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 10"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:177
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SPECIAL SECTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SPECIALE SECTIES"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:180
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The [sssd] section"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "De [sssd] sectie"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:189 sssd.conf.5.xml:2511
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Section parameters"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Sectie parameters"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:191
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "config_file_version (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "config_file_version (numeriek)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:194
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Indicates what is the syntax of the config file. SSSD 0.6.0 and later use "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"version 2."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Geeft aan welke syntaxis de configuratie gebruikt. SSSD 0.6.0 en hoger "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"gebruiken versie 2."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:200
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "services"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "diensten"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:203
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Comma separated list of services that are started when sssd itself starts."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Kommagescheiden lijst van diensten die gestart worden als sssd zelf start."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:207
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</phrase> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<phrase condition=\"with_autofs\">, autofs</phrase> <phrase condition="
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"with_ssh\">, ssh</phrase> <phrase condition=\"with_pac_responder\">, pac</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"phrase> <phrase condition=\"with_ifp\">, ifp</phrase>"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:217 sssd.conf.5.xml:507
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "reconnection_retries (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "reconnection_retries (numeriek)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:220 sssd.conf.5.xml:510
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Number of times services should attempt to reconnect in the event of a Data "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Provider crash or restart before they give up"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Aantal keer dat de service moet proberen om opnieuw te verbinden indien een "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Data Aanbieder crashed of opnieuw start voordat dit opgegeven wordt"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:225 sssd.conf.5.xml:515
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 3"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Standaard: 3"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:230
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "domains"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "domeinen"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:233
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A domain is a database containing user information. SSSD can use more "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains at the same time, but at least one must be configured or SSSD won't "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"start. This parameter described the list of domains in the order you want "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"them to be queried. A domain name should only consist of alphanumeric ASCII "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"characters, dashes, dots and underscores."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:245 sssd.conf.5.xml:2144
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "re_expression (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "re_expression (tekst)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:248
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Default regular expression that describes how to parse the string containing "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"user name and domain into these components."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:253
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Each domain can have an individual regular expression configured. For some "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ID providers there are also default regular expressions. See DOMAIN "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"SECTIONS for more info on these regular expressions."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:262 sssd.conf.5.xml:2195
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "full_name_format (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "full_name_format (tekst)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:265 sssd.conf.5.xml:2198
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"manvolnum> </citerefentry>-compatible format that describes how to compose a "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"fully qualified name from user name and domain name components."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:276 sssd.conf.5.xml:2209
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%1$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:277 sssd.conf.5.xml:2210
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "user name"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:280 sssd.conf.5.xml:2213
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%2$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:283 sssd.conf.5.xml:2216
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "domain name as specified in the SSSD config file."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:289 sssd.conf.5.xml:2222
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%3$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:292 sssd.conf.5.xml:2225
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"domain flat name. Mostly usable for Active Directory domains, both directly "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"configured or discovered via IPA trusts."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:273 sssd.conf.5.xml:2206
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"The following expansions are supported: <placeholder type=\"variablelist\" "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:302
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Each domain can have an individual format string configured. see DOMAIN "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"SECTIONS for more info on this option."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:308
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "try_inotify (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "try_inotify (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:311
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD monitors the state of resolv.conf to identify when it needs to update "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"its internal DNS resolver. By default, we will attempt to use inotify for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this, and will fall back to polling resolv.conf every five seconds if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"inotify cannot be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"SSSD houdt de stat van resolv.conf in de gaten om te zien wanneer de interne "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"DNS-resolver bijgewerkt moet worden. Standaard wordt er geprobeerd om "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"inotify te gebruiken en er wordt teruggevallen op iedere vijf seconden "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"kijken of resolv.conf gewijzigd is als er geen inotify beschikbaar is."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:319
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"There are some limited situations where it is preferred that we should skip "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"even trying to use inotify. In these rare cases, this option should be set "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to 'false'"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Er zijn een aantal situaties waarin het de voorkeur heeft dat we het gebruik "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"van inotify uitschakelen. In deze zeldzame gevallen kan de optie op 'false' "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"gezet worden"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:325
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: true on platforms where inotify is supported. False on other "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"platforms."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Standaard: true op systemen waar inotify is ondersteund. False op andere "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"systemen."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:329
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note: this option will have no effect on platforms where inotify is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"unavailable. On these platforms, polling will always be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Merk op: deze optie heeft geen effect op systemen waar inotify niet "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"beschikbaar is. Op deze systemen wordt altijd periodiek gekeken naar resolv."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"conf."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:336
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_rcache_dir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:339
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Directory on the filesystem where SSSD should store Kerberos replay cache "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"files."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Map in het bestandssysteem waarin SSSD Kerberos replay cache bestanden moet "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"opslaan."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:343
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SSSD to let libkrb5 decide the appropriate location for the replay cache."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:349
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: Distribution-specific and specified at build-time. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(__LIBKRB5_DEFAULTS__ if not configured)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:356
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "user (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:359
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The user to drop the privileges to where appropriate to avoid running as the "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"root user."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:364
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: not set, process will run as root"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:369
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "default_domain_suffix (string)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:372
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"This string will be used as a default domain name for all names without a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain name component. The main use case is environments where the primary "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain is intended for managing host policies and all users are located in a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"trusted domain. The option allows those users to log in just with their "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"user name without giving a domain name as well."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:382
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Please note that if this option is set all users from the primary domain "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"have to use their fully qualified name, e.g. user@domain.name, to log in. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Setting this option changes default of use_fully_qualified_names to True. It "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"is not allowed to use this option together with use_fully_qualified_names "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"set to False."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:391 sssd-ldap.5.xml:663 sssd-ldap.5.xml:1498
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1510 sssd-ldap.5.xml:1592 sssd-ad.5.xml:614
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:689 sssd-krb5.5.xml:410 sssd-krb5.5.xml:550
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:205 include/ldap_id_mapping.xml:216
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: not set"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:396
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "override_space (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:399
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This parameter will replace spaces (space bar) with the given character for "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"user and group names. e.g. (_). User name &quot;john doe&quot; will be "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"&quot;john_doe&quot; This feature was added to help compatibility with shell "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"scripts that have difficulty handling spaces, due to the default field "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"separator in the shell."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:408
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Please note it is a configuration error to use a replacement character that "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"might be used in user or group names. If a name contains the replacement "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"character SSSD tries to return the unmodified name but in general the result "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"of a lookup is undefined."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:416
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: not set (spaces will not be replaced)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:421
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "re_expression (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "certificate_verification (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "re_expression (tekst)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:429
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "no_ocsp"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:431
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Disables Online Certificate Status Protocol (OCSP) checks. This might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"needed if the OCSP servers defined in the certificate are not reachable from "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the client."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:439
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "no_verification"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:441
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Disables verification completely. This option should only be used for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"testing."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:447
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ocsp_default_responder=URL"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:449
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Sets the OCSP default responder which should be used instead of the one "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"mentioned in the certificate. URL must be replaced with the URL of the OCSP "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"default responder e.g. http://example.com:80/ocsp."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:455
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option must be used together with ocsp_default_responder_signing_cert."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:463
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ocsp_default_responder_signing_cert=NAME"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:465
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The nickname of the cert to trust (expected) to sign the OCSP responses. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The certificate with the given nickname must be availble in the systems NSS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"database."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:470
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "This option must be used together with ocsp_default_responder."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:424
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"With this parameter the certificate verification can be tuned with a comma "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"separated list of options. Supported options are: <placeholder type="
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"\"variablelist\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:477
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Unknown options are reported but ignored."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:480
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: not set, i.e. do not restrict certificate vertification"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:182
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Individual pieces of SSSD functionality are provided by special SSSD "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"services that are started and stopped together with SSSD. The services are "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"managed by a special service frequently called <quote>monitor</quote>. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>[sssd]</quote> section is used to configure the monitor as well as "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"some other important options like the identity domains. <placeholder type="
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:492
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SERVICES SECTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "SERVICES SECTIE"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:494
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Settings that can be used to configure different services are described in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this section. They should reside in the [<replaceable>$NAME</replaceable>] "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"section, for example, for NSS service, the section would be <quote>[nss]</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:501
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "General service configuration options"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Algemene service configuratie-opties"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:503
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "These options can be used to configure any service."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Deze opties kunnen gebruikt worden om services te configureren."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:520
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "fd_limit"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:523
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"This option specifies the maximum number of file descriptors that may be "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"opened at one time by this SSSD process. On systems where SSSD is granted "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"systems without this capability, the resulting value will be the lower value "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"of this or the limits.conf \"hard\" limit."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:532
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: 8192 (or limits.conf \"hard\" limit)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:537
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "client_idle_timeout"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:540
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option specifies the number of seconds that a client of an SSSD process "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"can hold onto a file descriptor without communicating on it. This value is "
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"limited in order to avoid resource exhaustion on the system."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:547 sssd.conf.5.xml:563 sssd.conf.5.xml:595
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:842 sssd.conf.5.xml:1034 sssd.conf.5.xml:1467
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1237
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 60"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:552 sssd.conf.5.xml:1456
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "force_timeout (integer)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:555 sssd.conf.5.xml:1459
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If a service is not responding to ping checks (see the <quote>timeout</"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"quote> option), it is first sent the SIGTERM signal that instructs it to "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"quit gracefully. If the service does not terminate after "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<quote>force_timeout</quote> seconds, the monitor will forcibly shut it down "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"by sending a SIGKILL signal."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:568
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "offline_timeout (integer)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:571
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"When SSSD switches to offline mode the amount of time before it tries to go "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"back online will increase based upon the time spent disconnected. This "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"value is in seconds and calculated by the following:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:578
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "offline_timeout + random_offset"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:581
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The random offset can increment up to 30 seconds. After each unsuccessful "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attempt to go online, the new interval is recalculated by the following:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:586
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "new_interval = old_interval*2 + random_offset"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:589
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Note that the maximum length of each interval is currently limited to one "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"hour. If the calculated length of new_interval is greater than an hour, it "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"will be forced to one hour."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:603
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "NSS configuration options"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "NSS configuratie-opties"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:605
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"These options can be used to configure the Name Service Switch (NSS) service."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Deze opties kunnen worden gebruikt om de Name Serice Switch (NSS) service te "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"configurere."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:610
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "enum_cache_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "enum_cache_timeout (numeriek)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:613
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"How many seconds should nss_sss cache enumerations (requests for info about "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"all users)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Hoeveel seconden zouden nss_sss cache enumeraties (verzoeken om informatie "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"over alle gebruikers)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:617
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 120"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "Standaard: 120"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:622
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "entry_cache_nowait_percentage (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "entry_cache_nowait_percentage (numeriek)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:625
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The entry cache can be set to automatically update entries in the background "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"if they are requested beyond a percentage of the entry_cache_timeout value "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for the domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:631
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For example, if the domain's entry_cache_timeout is set to 30s and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"entry_cache_nowait_percentage is set to 50 (percent), entries that come in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"after 15 seconds past the last cache update will be returned immediately, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"but the SSSD will go and update the cache on its own, so that future "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"requests will not need to block waiting for a cache update."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:641
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Valid values for this option are 0-99 and represent a percentage of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"entry_cache_timeout for each domain. For performance reasons, this "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"percentage will never reduce the nowait timeout to less than 10 seconds. (0 "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"disables this feature)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:649
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 50"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:654
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "entry_negative_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr "entry_negative_timeout (numeriek)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:657
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies for how many seconds nss_sss should cache negative cache hits "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(that is, queries for invalid database entries, like nonexistent ones) "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"before asking the back end again."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:663 sssd.conf.5.xml:1224
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 15"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:668
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "entry_negative_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "local_negative_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "entry_negative_timeout (numeriek)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:671
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies for how many seconds nss_sss should keep local users and groups in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"negative cache before trying to look it up in the back end again."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:676 sssd.conf.5.xml:1022 sssd.conf.5.xml:2445 sssd.8.xml:79
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 0"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "Standaard: 0"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:681
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "filter_users, filter_groups (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:684
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Exclude certain users or groups from being fetched from the sss NSS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"database. This is particularly useful for system accounts. This option can "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"also be set per-domain or include fully-qualified names to filter only users "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from the particular domain."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:691
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: The filter_groups option doesn't affect inheritance of nested group "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"members, since filtering happens after they are propagated for returning via "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NSS. E.g. a group having a member group filtered out will still have the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"member users of the latter listed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:699
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: root"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:704
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "filter_users_in_groups (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:707
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If you want filtered user still be group members set this option to false."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:718
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "fallback_homedir (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:721
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Set a default template for a user's home directory if one is not specified "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"explicitly by the domain's data provider."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:726
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"The available values for this option are the same as for override_homedir."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:732
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fallback_homedir = /home/%u\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek" "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:730 sssd.conf.5.xml:1101 sssd.conf.5.xml:1120
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-krb5.5.xml:533 include/override_homedir.xml:55
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "example: <placeholder type=\"programlisting\" id=\"0\"/>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:736
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: not set (no substitution for unset home directories)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:742
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "override_shell (string)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:745
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Override the login shell for all users. This option supersedes any other "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"shell options if it takes effect and can be set either in the [nss] section "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"or per-domain."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:751
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Default: not set (SSSD will use the value retrieved from LDAP)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:757
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "allowed_shells (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:760
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Restrict user shell to one of the listed values. The order of evaluation is:"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:763
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:767
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"quote>, use the value of the shell_fallback parameter."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:772
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"3. If the shell is not in the allowed_shells list and not in <quote>/etc/"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"shells</quote>, a nologin shell is used."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:777
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The wildcard (*) can be used to allow any shell."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:780
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The (*) is useful if you want to use shell_fallback in case that user's "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"shell is not in <quote>/etc/shells</quote> and maintaining list of all "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"allowed shells in allowed_shells would be to much overhead."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:787
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "An empty string for shell is passed as-is to libc."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:790
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"The <quote>/etc/shells</quote> is only read on SSSD start up, which means "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"that a restart of the SSSD is required in case a new shell is installed."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:794
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: Not set. The user shell is automatically used."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:799
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "vetoed_shells (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:802
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Replace any instance of these shells with the shell_fallback"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:807
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "shell_fallback (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:810
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"The default shell to use if an allowed shell is not installed on the machine."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:814
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: /bin/sh"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:819
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "default_shell"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:822
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The default shell to use if the provider does not return one during lookup. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option can be specified globally in the [nss] section or per-domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:828
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Default: not set (Return NULL if no shell is specified and rely on libc to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"substitute something sensible when necessary, usually /bin/sh)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:835 sssd.conf.5.xml:1027
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "get_domains_timeout (int)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:838 sssd.conf.5.xml:1030
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies time in seconds for which the list of subdomains will be "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"considered valid."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:847
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "memcache_timeout (int)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:850
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Specifies time in seconds for which records in the in-memory cache will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"valid."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:854 sssd.conf.5.xml:1338 sssd-ldap.5.xml:706
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: 300"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:857
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"client applications will not use the fast in-memory cache."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:865 sssd-ifp.5.xml:74
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "user_attributes (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:868
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Some of the additional NSS responder requests can return more attributes "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"than just the POSIX ones defined by the NSS interface. The list of "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"attributes is controlled by this option. It is handled the same way as the "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<quote>user_attributes</quote> option of the InfoPipe responder (see "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"manvolnum> </citerefentry> for details) but with no default values."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:881
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"To make configuration more easy the NSS responder will check the InfoPipe "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"option if it is not set for the NSS responder."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:886
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: not set, fallback to InfoPipe option"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:893
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "PAM configuration options"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:895
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"These options can be used to configure the Pluggable Authentication Module "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(PAM) service."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:900
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "offline_credentials_expiration (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:903
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If the authentication provider is offline, how long should we allow cached "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"logins (in days since the last successful online login)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:908 sssd.conf.5.xml:921
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 0 (No limit)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:914
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "offline_failed_login_attempts (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:917
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If the authentication provider is offline, how many failed login attempts "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are allowed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:927
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "offline_failed_login_delay (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:930
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The time in minutes which has to pass after offline_failed_login_attempts "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"has been reached before a new login attempt is possible."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:935
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If set to 0 the user cannot authenticate offline if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"offline_failed_login_attempts has been reached. Only a successful online "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"authentication can enable offline authentication again."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:941 sssd.conf.5.xml:994
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 5"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:947
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pam_verbosity (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:950
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Controls what kind of messages are shown to the user during authentication. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The higher the number to more messages are displayed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:955
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Currently sssd supports the following values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:958
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>0</emphasis>: do not show any message"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:961
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>1</emphasis>: show only important messages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:965
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>2</emphasis>: show informational messages"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:968
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>3</emphasis>: show all messages and debug information"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:972 sssd.8.xml:63
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 1"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:977
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pam_id_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:980
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For any PAM request while SSSD is online, the SSSD will attempt to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"immediately update the cached identity information for the user in order to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ensure that authentication takes place with the latest information."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:986
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"A complete PAM conversation may perform multiple PAM requests, such as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"account management and session opening. This option controls (on a per-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"client-application basis) how long (in seconds) we can cache the identity "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"information to avoid excessive round-trips to the identity provider."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1000
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pam_pwd_expiration_warning (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1003 sssd.conf.5.xml:1670
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Display a warning N days before the password expires."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1006
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that the backend server has to provide information about the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"expiration time of the password. If this information is missing, sssd "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"cannot display a warning."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1012 sssd.conf.5.xml:1673
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"If zero is set, then this filter is not applied, i.e. if the expiration "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"warning was received from backend server, it will automatically be displayed."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1017
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"This setting can be overridden by setting <emphasis>pwd_expiration_warning</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"emphasis> for a particular domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1039
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "pam_trusted_users (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1042
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"allowed to run PAM conversations against trusted domains. Users not "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"included in this list can only access domains marked as public with "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>pam_public_domains</quote>. User names are resolved to UIDs at "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"startup."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1052
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: All users are considered trusted by default"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1056
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Please note that UID 0 is always allowed to access the PAM responder even in "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"case it is not in the pam_trusted_users list."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1063
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "pam_public_domains (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1066
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Specifies the comma-separated list of domain names that are accessible even "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"to untrusted users."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1070
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Two special values for pam_public_domains option are defined:"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1074
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"all (Untrusted users are allowed to access all domains in PAM responder.)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1078
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"none (Untrusted users are not allowed to access any domains PAM in "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"responder.)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1082 sssd.conf.5.xml:1107 sssd.conf.5.xml:1126
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1450 sssd.conf.5.xml:2381 sssd-ldap.5.xml:1793
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: none"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1087
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "pam_account_expired_message (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1090
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Allows a custom expiration message to be set, replacing the default "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"'Permission denied' message."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1095
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Please be aware that message is only printed for the SSH service "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"unless pam_verbostiy is set to 3 (show all messages and debug information)."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1103
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"pam_account_expired_message = Account expired, please contact help desk.\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1112
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_account_locked_message (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1115
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Allows a custom lockout message to be set, replacing the default 'Permission "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"denied' message."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1122
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"pam_account_locked_message = Account locked, please contact help desk.\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1131
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_cert_auth (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1134
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Enable certificate based Smartcard authentication. Since this requires "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"additional communication with the Smartcard which will delay the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"authentication process this option is disabled by default."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1140 sssd-ldap.5.xml:1021 sssd-ldap.5.xml:1048
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1339 sssd-ldap.5.xml:1360 sssd-ldap.5.xml:1866
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:244
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: False"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1145
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "full_name_format (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_cert_db_path (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "full_name_format (tekst)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1148
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The path to the certificate database which contain the PKCS#11 modules to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"access the Smartcard."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1152
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: /etc/pki/nssdb (NSS version)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1157
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "enum_cache_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "p11_child_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "enum_cache_timeout (numeriek)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1160
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "How many seconds will pam_sss wait for p11_child to finish."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1173
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "SUDO configuration options"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1175
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"These options can be used to configure the sudo service. The detailed "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"instructions for configuration of <citerefentry> <refentrytitle>sudo</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1192
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "sudo_timed (bool)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1195
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"that implement time-dependent sudoers entries."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1208
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "AUTOFS configuration options"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1210
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "These options can be used to configure the autofs service."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1214
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "autofs_negative_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1217
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Specifies for how many seconds should the autofs responder negative cache "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"hits (that is, queries for invalid map entries, like nonexistent ones) "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"before asking the back end again."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1233
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "SSH configuration options"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1235
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "These options can be used to configure the SSH service."
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1239
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ssh_hash_known_hosts (bool)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1242
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
45db68ae27147955a4be4c2c772041824c0dc00fStephen Gallagher"Whether or not to hash host names and addresses in the managed known_hosts "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"file."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1251
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ssh_known_hosts_timeout (integer)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1254
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"How many seconds to keep a host in the managed known_hosts file after its "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"host keys were requested."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1258
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 180"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1263
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ca_db (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1266
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Path to a storage of trusted CA certificates. The option is used to validate "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"user certificates before deriving public ssh keys from them."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1271
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: /etc/pki/nssdb"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1279
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "PAC responder configuration options"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1281
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"The PAC responder works together with the authorization data plugin for MIT "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PAC data during a GSSAPI authentication to the PAC responder. The sub-domain "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"provider collects domain SID and ID ranges of the domain the client is "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"joined to and of remote trusted domains from the local domain controller. "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If the PAC is decoded and evaluated some of the following operations are "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"done:"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1290
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If the remote user does not exist in the cache, it is created. The uid is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"determined with the help of the SID, trusted domains will have UPGs and the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"gid will have the same value as the uid. The home directory is set based on "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the subdomain_homedir parameter. The shell will be empty by default, i.e. "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the system defaults are used, but can be overwritten with the default_shell "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"parameter."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1298
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"If there are SIDs of groups from domains sssd knows about, the user will be "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"added to those groups."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1304
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "These options can be used to configure the PAC responder."
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1308 sssd-ifp.5.xml:50
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "allowed_uids (string)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1311
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"allowed to access the PAC responder. User names are resolved to UIDs at "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"startup."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1317
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: 0 (only the root user is allowed to access the PAC responder)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1321
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Please note that although the UID 0 is used as the default it will be "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"overwritten with this option. If you still want to allow the root user to "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"access the PAC responder, which would be the typical case, you have to add 0 "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"to the list of allowed UIDs as well."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1330
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "enum_cache_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pac_lifetime (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "enum_cache_timeout (numeriek)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1333
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"data can be used to determine the group memberships of a user."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1348
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "DOMAIN SECTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1355
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "min_id,max_id (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1358
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"UID and GID limits for the domain. If a domain contains an entry that is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"outside these limits, it is ignored."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1363
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"For users, this affects the primary GID limit. The user will not be returned "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to NSS if either the UID or the primary GID is outside the range. For non-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"primary group memberships, those that are in range will be reported as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"expected."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1370
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"These ID limits affect even saving entries to cache, not only returning them "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"by name or ID."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1374
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 1 for min_id, 0 (no limit) for max_id"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1380
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "enumerate (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1383
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Determines if a domain can be enumerated. This parameter can have one of the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"following values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1387
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "TRUE = Users and groups are enumerated"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1390
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FALSE = No enumerations for this domain"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1393 sssd.conf.5.xml:1625 sssd.conf.5.xml:1792
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: FALSE"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1396
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note: Enabling enumeration has a moderate performance impact on SSSD while "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"enumeration is running. It may take up to several minutes after SSSD startup "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to fully complete enumerations. During this time, individual requests for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"information will go directly to LDAP, though it may be slow, due to the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"heavy enumeration processing. Saving a large number of entries to cache "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"after the enumeration completes might also be CPU intensive as the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"memberships have to be recomputed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1409
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"While the first enumeration is running, requests for the complete user or "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"group lists may return no results until it completes."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1414
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Further, enabling enumeration may increase the time necessary to detect "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"network disconnection, as longer timeouts are required to ensure that "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"enumeration lookups are completed successfully. For more information, refer "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to the man pages for the specific id_provider in use."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1422
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"For the reasons cited above, enabling enumeration is not recommended, "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"especially in large environments."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1430
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "subdomain_enumerate (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1437
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "all"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1438
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "All discovered trusted domains will be enumerated"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1441
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "none"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1442
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "No discovered trusted domains will be enumerated"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1433
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Whether any of autodetected trusted domains should be enumerated. The "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"supported values are: <placeholder type=\"variablelist\" id=\"0\"/> "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Optionally, a list of one or more domain names can enable enumeration just "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"for these trusted domains."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1473
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "entry_cache_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1476
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"How many seconds should nss_sss consider entries valid before asking the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"backend again"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1480
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The cache expiration timestamps are stored as attributes of individual "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"objects in the cache. Therefore, changing the cache timeout only has effect "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"for newly added or expired entries. You should run the <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> tool in order to force refresh of entries that have already "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"been cached."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1493
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 5400"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1499
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_user_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1502
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider user entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1506 sssd.conf.5.xml:1519 sssd.conf.5.xml:1532
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1545 sssd.conf.5.xml:1558 sssd.conf.5.xml:1572
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1586
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: entry_cache_timeout"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1512
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_group_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1515
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider group entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1525
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_netgroup_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1528
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider netgroup entries valid before "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"asking the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1538
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_service_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1541
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider service entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1551
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "entry_cache_sudo_timeout (integer)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1554
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds should sudo consider rules valid before asking the backend "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"again"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1564
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "entry_cache_autofs_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1567
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"How many seconds should the autofs service consider automounter maps valid "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"before asking the backend again"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1578
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "entry_cache_ssh_host_timeout (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1581
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"How many seconds to keep a host ssh key after refresh. IE how long to cache "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the host key for."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1592
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "refresh_expired_interval (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1595
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies how many seconds SSSD has to wait before triggering a background "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"refresh task which will refresh all expired or nearly expired records."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1600
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The background refresh will process users, groups and netgroups in the cache."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1604
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "You can consider setting this value to 3/4 * entry_cache_timeout."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1608 sssd-ldap.5.xml:730 sssd-ipa.5.xml:227
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Default: 0 (disabled)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1614
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "cache_credentials (bool)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1617
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Determines if user credentials are also cached in the local LDB cache"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1621
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "User credentials are stored in a SHA512 hash, not in plaintext"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1631
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "cache_credentials_minimal_first_factor_length (int)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1634
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"If 2-Factor-Authentication (2FA) is used and credentials should be saved "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"this value determines the minimal length the first authentication factor "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"(long term password) must have to be saved as SHA512 hash into the cache."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1641
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"This should avoid that the short PINs of a PIN based 2FA scheme are saved in "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the cache which would make them easy targets for brute-force attacks."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1646
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: 8"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1652
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "account_cache_expiration (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1655
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Number of days entries are left in cache after last successful login before "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"being removed during a cleanup of the cache. 0 means keep forever. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"value of this parameter must be greater than or equal to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"offline_credentials_expiration."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1662
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 0 (unlimited)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1667
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "pwd_expiration_warning (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1678
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Please note that the backend server has to provide information about the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"expiration time of the password. If this information is missing, sssd "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"cannot display a warning. Also an auth provider has to be configured for the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"backend."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1685
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: 7 (Kerberos), 0 (LDAP)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1691
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "id_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1694
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The identification provider used for the domain. Supported ID providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1698
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "<quote>proxy</quote>: Support a legacy NSS provider"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1701 sssd.conf.5.xml:1838
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<quote>local</quote>: SSSD internal provider for local users"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1705
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1713 sssd.conf.5.xml:1818 sssd.conf.5.xml:1873
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1936
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"provider. See <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"FreeIPA."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1722 sssd.conf.5.xml:1827 sssd.conf.5.xml:1882
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1945
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ad</quote>: Active Directory provider. See <citerefentry> "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry> for more information on configuring Active Directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1733
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "use_fully_qualified_names (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1736
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Use the full name and domain (as formatted by the domain's full_name_format) "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"as the user's login name reported to NSS."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1741
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If set to TRUE, all requests to this domain must use fully qualified names. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For example, if used in LOCAL domain that contains a \"test\" user, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>getent passwd test</command> wouldn't find the user while "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>getent passwd test@LOCAL</command> would."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1749
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"NOTE: This option has no effect on netgroup lookups due to their tendency to "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"include nested netgroups without qualified names. For netgroups, all domains "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"will be searched when an unqualified name is requested."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1756
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: FALSE (TRUE if default_domain_suffix is used)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1762
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ignore_group_members (bool)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1765
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Do not return group members for group lookups."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1768
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If set to TRUE, the group membership attribute is not requested from the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap server, and group members are not returned when processing group lookup "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"calls, such as <citerefentry> <refentrytitle>getgrnam</refentrytitle> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<manvolnum>3</manvolnum> </citerefentry> or <citerefentry> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<refentrytitle>getgrgid</refentrytitle> <manvolnum>3</manvolnum> </"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"citerefentry>. As an effect, <quote>getent group $groupname</quote> would "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"return the requested group as if it was empty."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1786
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Enabling this option can also make access provider checks for group "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"membership significantly faster, especially for groups containing many "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"members."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1797
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "auth_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1800
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The authentication provider used for the domain. Supported auth providers "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1804 sssd.conf.5.xml:1866
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> for native LDAP authentication. See <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> for more information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1811
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>krb5</quote> for Kerberos authentication. See <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> for more information on configuring Kerberos."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1835
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>proxy</quote> for relaying authentication to some other PAM target."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1842
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>none</quote> disables authentication explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1845
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can handle "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"authentication requests."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1851
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "access_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1854
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The access control provider used for the domain. There are two built-in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access providers (in addition to any included in installed backends) "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Internal special providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1860
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>permit</quote> always allow access. It's the only permitted access "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"provider for a local domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1863
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>deny</quote> always deny access."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1890
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>simple</quote> access control based on access or deny lists. See "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum></citerefentry> for more information on configuring the simple "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"access module."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1897
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>krb5</quote>: .k5login based access control. See <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> for more information on configuring Kerberos."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1904
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<quote>proxy</quote> for relaying access control to another PAM module."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1907
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <quote>permit</quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1912
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "chpass_provider (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1915
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The provider which should handle change password operations for the domain. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Supported change password providers are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1920
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap</quote> to change a password stored in a LDAP server. See "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1928
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>krb5</quote> to change the Kerberos password. See <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> for more information on configuring Kerberos."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1953
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>proxy</quote> for relaying password changes to some other PAM target."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1957
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<quote>none</quote> disallows password changes explicitly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1960
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: <quote>auth_provider</quote> is used if it is set and can handle "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"change password requests."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1967
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "sudo_provider (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1970
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The SUDO provider used for the domain. Supported SUDO providers are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1974
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"citerefentry> for more information on configuring LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1982
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"settings."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1986
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>ad</quote> the same as <quote>ldap</quote> but with AD default "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"settings."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1990
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<quote>none</quote> disables SUDO explicitly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1993 sssd.conf.5.xml:2071 sssd.conf.5.xml:2112
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2137
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: The value of <quote>id_provider</quote> is used if it is set."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1997
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The detailed instructions for configuration of sudo_provider are in the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>. There are many configuration "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"options that can be used to adjust the behavior. Please refer to "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2014
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "selinux_provider (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2017
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The provider which should handle loading of selinux settings. Note that this "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"provider will be called right after access provider ends. Supported selinux "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"providers are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2023
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ipa</quote> to load selinux settings from an IPA server. See "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2031
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<quote>none</quote> disallows fetching selinux settings explicitly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2034
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can handle "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"selinux loading requests."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2040
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "subdomains_provider (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2043
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The provider which should handle fetching of subdomains. This value should "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"be always the same as id_provider. Supported subdomain providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2049
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load a list of subdomains from an IPA server. See "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2058
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<quote>ad</quote> to load a list of subdomains from an Active Directory "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"the AD provider."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2067
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disallows fetching subdomains explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2078
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "autofs_provider (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2081
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The autofs provider used for the domain. Supported autofs providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2085
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more information on configuring LDAP."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2092
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2100
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> for more information on configuring the AD provider."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2109
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disables autofs explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2119
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "hostid_provider (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2122
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The provider used for retrieving host identity information. Supported "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"hostid providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2126
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load host identity stored in an IPA server. See "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2134
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disables hostid explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2147
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Regular expression for this domain that describes how to parse the string "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"containing user name and domain into these components. The \"domain\" can "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"match either the SSSD configuration domain name, or, in the case of IPA "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"trust subdomains and Active Directory domains, the flat (NetBIOS) name of "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the domain."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2156
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Default for the AD and IPA provider: <quote>(((?P&lt;domain&gt;[^\\\\]+)\\"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"\\(?P&lt;name&gt;.+$))|((?P&lt;name&gt;[^@]+)@(?P&lt;domain&gt;.+$))|(^(?"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"P&lt;name&gt;[^@\\\\]+)$))</quote> which allows three different styles for "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"user names:"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2161
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "username"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2164
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "username@domain.name"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2167
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "domain\\username"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2170
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"While the first two correspond to the general default the third one is "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"introduced to allow easy integration of users from Windows domains."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2175
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Default: <quote>(?P&lt;name&gt;[^@]+)@?(?P&lt;domain&gt;[^@]*$)</quote> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"which translates to \"the name is everything up to the <quote>@</quote> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"sign, the domain everything after that\""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Standaard: <quote>(?P&lt;name&gt;[^@]+)@?(?P&lt;domain&gt;[^@]*$)</quote> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"wat zich vertaalt tot \"de gebruikersnaam is alles tot <quote>@</quote> , "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"het domein alles daarna\""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2181
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PLEASE NOTE: the support for non-unique named subpatterns is not available "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"on all platforms (e.g. RHEL5 and SLES10). Only platforms with libpcre "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"version 7 or higher can support non-unique named subpatterns."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2188
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PLEASE NOTE ALSO: older version of libpcre only support the Python syntax (?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"P&lt;name&gt;) to label subpatterns."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"MER OOK OP: oudere versies van libpcre ondersteunen alleen de Pyton syntaxis "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"(?P&lt;name&gt;) om subpatronen aan te geven."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2235
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: <quote>%1$s@%2$s</quote>."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "Standaard: <quote>%1$s@%2$s</quote>."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2241
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "lookup_family_order (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2244
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Provides the ability to select preferred address family to use when "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"performing DNS lookups."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2248
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Supported values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2251
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2254
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2257
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2260
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2263
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: ipv4_first"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2269
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dns_resolver_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2272
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Defines the amount of time (in seconds) to wait for a reply from the DNS "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"resolver before assuming that it is unreachable. If this timeout is reached, "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the domain will continue to operate in offline mode."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2278 sssd-ldap.5.xml:1221 sssd-ldap.5.xml:1263
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1281 sssd-krb5.5.xml:248
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "Default: 6"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2284
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "dns_discovery_domain (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2287
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If service discovery is used in the back end, specifies the domain part of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the service discovery DNS query."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2291
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Use the domain part of machine's hostname"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2297
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "override_gid (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2300
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Override the primary GID value with the one specified."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2306
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "case_sensitive (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2314
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "True"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2317
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Case sensitive. This value is invalid for AD provider."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2323
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "False"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2325
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Case insensitive."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2329
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Preserving"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2332
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Same as False (case insensitive), but does not lowercase names in the result "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"of NSS operations. Note that name aliases (and in case of services also "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"protocol names) are still lowercased in the output."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2309
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Treat user and group names as case sensitive. At the moment, this option is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"not supported in the local provider. Possible option values are: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2344
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: True (False for AD provider)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2350
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "subdomain_inherit (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2353
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies a list of configuration parameters that should be inherited by a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"subdomain. Please note that only selected parameters can be inherited. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Currently the following options can be inherited:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2359
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ignore_group_members"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2362
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_purge_cache_timeout"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2365 sssd-ldap.5.xml:1054
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_use_tokengroups"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2368
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_user_principal"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2371
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is not set explicitly)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2377
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"subdomain_inherit = ldap_purge_cache_timeout\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2375
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2384
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Note: This option only works with the IPA and AD provider."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2391
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "subdomain_homedir (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2402
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%F"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2403
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "flat (NetBIOS) name of a subdomain."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2394
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Use this homedir as default value for all subdomains within this domain in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"IPA AD trust. See <emphasis>override_homedir</emphasis> for info about "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"possible values. In addition to those, the expansion below can only be used "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"with <emphasis>subdomain_homedir</emphasis>. <placeholder type="
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\"variablelist\" id=\"0\"/>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2408
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The value can be overridden by <emphasis>override_homedir</emphasis> option."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2412
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: <filename>/home/%d/%u</filename>"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2417
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "realmd_tags (string)"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2420
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Various tags stored by the realmd configuration service for this domain."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2426
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#, fuzzy
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#| msgid "enum_cache_timeout (integer)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid "cached_auth_timeout (int)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr "enum_cache_timeout (numeriek)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2429
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Specifies time in seconds since last successful online authentication for "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"which user will be authenticated using cached credentials while SSSD is in "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"the online mode."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2435
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid "Special value 0 implies that this feature is disabled."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2439
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Please note that if <quote>cached_auth_timeout</quote> is longer than "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>pam_id_timeout</quote> then the back end could be called to handle "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>initgroups.</quote>"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:1350
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"These configuration options can be present in a domain configuration "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"section, that is, in a section called <quote>[domain/<replaceable>NAME</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2457
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "proxy_pam_target (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2460
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The proxy target PAM proxies to."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2463
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: not set by default, you have to take an existing pam configuration "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"or create a new one and add the service name here."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2471
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "proxy_lib_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2474
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The name of the NSS library to use in proxy domains. The NSS functions "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"searched for in the library are in the form of _nss_$(libName)_$(function), "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"for example _nss_files_getpwent."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2484
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "proxy_fast_alias (boolean)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2487
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When a user or group is looked up by name in the proxy provider, a second "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"lookup by ID is performed to \"canonicalize\" the name in case the requested "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"name was an alias. Setting this option to true would cause the SSSD to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"perform the ID lookup from cache for performance reasons."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2453
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Options valid for proxy domains. <placeholder type=\"variablelist\" id="
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2504
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The local domain section"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2506
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This section contains settings for domain that stores users and groups in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"SSSD native database, that is, a domain that uses "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>id_provider=local</replaceable>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2513
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "default_shell (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2516
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The default shell for users created with SSSD userspace tools."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2520
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <filename>/bin/bash</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2525
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "base_directory (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2528
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The tools append the login name to <replaceable>base_directory</replaceable> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"and use that as the home directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2533
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <filename>/home</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2538
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "create_homedir (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2541
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Indicate if a home directory should be created by default for new users. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Can be overridden on command line."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2545 sssd.conf.5.xml:2557
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: TRUE"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2550
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "remove_homedir (bool)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2553
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Indicate if a home directory should be removed by default for deleted "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"users. Can be overridden on command line."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2562
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "homedir_umask (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2565
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Used by <citerefentry> <refentrytitle>sss_useradd</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>8</manvolnum> </citerefentry> to specify the default permissions "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"on a newly created home directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2573
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 077"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2578
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "skel_dir (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2581
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The skeleton directory, which contains files and directories to be copied in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the user's home directory, when the home directory is created by "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sss_useradd</refentrytitle> <manvolnum>8</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2591
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <filename>/etc/skel</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2596
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "mail_dir (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2599
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The mail spool directory. This is needed to manipulate the mailbox when its "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"corresponding user account is modified or deleted. If not specified, a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"default value is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2606
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <filename>/var/mail</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2611
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "userdel_cmd (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2614
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The command that is run after a user is removed. The command us passed the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"username of the user being removed as the first and only parameter. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"return code of the command is not taken into account."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2620
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: None, no command is run"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2630 sssd-ldap.5.xml:2632 sssd-simple.5.xml:131
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:717 sssd-ad.5.xml:965 sssd-krb5.5.xml:564
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:98
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "EXAMPLE"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2636
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"[sssd]\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domains = LDAP\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"services = nss, pam\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"config_file_version = 2\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"[nss]\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"filter_groups = root\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"filter_users = root\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"[pam]\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"[domain/LDAP]\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"id_provider = ldap\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_uri = ldap://ldap.example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"ldap_search_base = dc=example,dc=com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"auth_provider = krb5\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"krb5_server = kerberos.example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"krb5_realm = EXAMPLE.COM\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"cache_credentials = true\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"min_id = 10000\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"max_id = 20000\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"enumerate = False\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:2632
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The following example shows a typical SSSD config. It does not describe "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"configuration of the domains themselves - refer to documentation on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"configuring domains for more details. <placeholder type=\"programlisting\" "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-ldap"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD LDAP provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:23
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of LDAP domains for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"</citerefentry>. Refer to the <quote>FILE FORMAT</quote> section of the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> manual page for detailed syntax information."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:35
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "You can configure SSSD to use more than one LDAP domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:38
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP back end supports id, auth, access and chpass providers. If you want to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"authenticate against an LDAP server either TLS/SSL or LDAPS is required. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sssd</command> <emphasis>does not</emphasis> support authentication "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"over an unencrypted channel. If the LDAP server is used only as an identity "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"provider, an encrypted channel is not needed. Please refer to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<quote>ldap_access_filter</quote> config option for more information about "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"using LDAP as an access provider."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:49 sssd-simple.5.xml:69 sssd-ipa.5.xml:70 sssd-ad.5.xml:89
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:63 sssd-ifp.5.xml:44
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "CONFIGURATION OPTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:60
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ldap_uri, ldap_backup_uri (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:63
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"should connect in the order of preference. Refer to the <quote>FAILOVER</"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"quote> section for more information on failover and server redundancy. If "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"neither option is specified, service discovery is enabled. For more "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"information, refer to the <quote>SERVICE DISCOVERY</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:70
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "The format of the URI must match the format defined in RFC 2732:"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:73
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "ldap[s]://&lt;host&gt;[:port]"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ldap.5.xml:76
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"For explicit IPv6 addresses, &lt;host&gt; must be enclosed in brackets []"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:79
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "example: ldap://[fc00::126:25]:389"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:85
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:88
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"should connect in the order of preference to change the password of a user. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Refer to the <quote>FAILOVER</quote> section for more information on "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"failover and server redundancy."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:95
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "To enable service discovery ldap_chpass_dns_service_name must be set."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:99
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: empty, i.e. ldap_uri is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:105
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:108
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The default base DN to use for performing LDAP user operations."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#: sssd-ldap.5.xml:112
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Starting with SSSD 1.7.0, SSSD supports multiple search bases using the "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"syntax:"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:116
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:119
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:122 include/ldap_search_bases.xml:18
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"The filter must be a valid LDAP search filter as specified by http://www."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ietf.org/rfc/rfc2254.txt"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:126 sssd-ldap.5.xml:646 sssd-ad.5.xml:220
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:137 sss_override.8.xml:234
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "Examples:"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:129
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = dc=example,dc=com (which is equivalent to) "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = dc=example,dc=com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:134
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"(host=thishost)?dc=example.com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:137
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Note: It is unsupported to have multiple search bases which reference "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"identically-named objects (for example, groups with the same name in two "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"different search bases). This will lead to unpredictable behavior on client "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"machines."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:144
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Default: If not set, the value of the defaultNamingContext or namingContexts "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"attribute from the RootDSE of the LDAP server is used. If "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"defaultNamingContext does not exist or has an empty value namingContexts is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"used. The namingContexts attribute must have a single value with the DN of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the search base of the LDAP server to make this work. Multiple values are "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are not supported."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:158
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_schema (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:161
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the Schema Type in use on the target LDAP server. Depending on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the selected schema, the default attribute names retrieved from the servers "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"may vary. The way that some attributes are handled may also differ."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:168
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Four schema types are currently supported:"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:172
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "rfc2307"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:177
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "rfc2307bis"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:182
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "IPA"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:187
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "AD"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:193
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"The main difference between these schema types is how group memberships are "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"recorded in the server. With rfc2307, group members are listed by name in "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"the <emphasis>memberUid</emphasis> attribute. With rfc2307bis and IPA, "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"group members are listed by DN and stored in the <emphasis>member</emphasis> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"attribute. The AD schema type sets the attributes to correspond with Active "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Directory 2008r2 values."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:203
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: rfc2307"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:209
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_default_bind_dn (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:212
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The default bind DN to use for performing LDAP operations."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:219
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_default_authtok_type (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:222
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The type of the authentication token of the default bind DN."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:226
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The two mechanisms currently supported are:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:229
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "password"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:232
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "obfuscated_password"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:235
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: password"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:241
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_default_authtok (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:244
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The authentication token of the default bind DN. Only clear text passwords "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are currently supported."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:251
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_object_class (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:254
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The object class of a user entry in LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:257
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: posixAccount"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:263
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:266
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's login name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:270
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: uid"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:276
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_uid_number (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:279
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's id."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:283
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: uidNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:289
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gid_number (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:292
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's primary group id."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:296 sssd-ldap.5.xml:863
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: gidNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:302
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_gecos (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:305
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's gecos field."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:309
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: gecos"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:315
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_home_directory (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:318
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "The LDAP attribute that contains the name of the user's home directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:322
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: homeDirectory"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:328
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shell (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:331
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that contains the path to the user's default shell."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:335
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: loginShell"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:341
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_user_uuid (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd-ldap.5.xml:344
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:348 sssd-ldap.5.xml:889
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Default: not set in the general case, objectGUID for AD and ipaUniqueID for "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"IPA"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:355
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_user_objectsid (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:358
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The LDAP attribute that contains the objectSID of an LDAP user object. This "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"is usually only necessary for ActiveDirectory servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:363 sssd-ldap.5.xml:904
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: objectSid for ActiveDirectory, not set for other servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:370
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_modify_timestamp (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:373 sssd-ldap.5.xml:914 sssd-ldap.5.xml:1137
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The LDAP attribute that contains timestamp of the last modification of the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"parent object."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:377 sssd-ldap.5.xml:918 sssd-ldap.5.xml:1144
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: modifyTimestamp"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:383
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_last_change (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:386
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (date of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the last password change)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:396
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowLastChange"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:402
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_min (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:405
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (minimum "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"password age)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:414
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowMin"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:420
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_max (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:423
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (maximum "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"password age)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:432
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowMax"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:438
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_warning (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:441
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"(password warning period)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:451
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowWarning"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:457
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_inactive (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:460
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"(password inactivity period)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:470
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowInactive"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:476
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_shadow_expire (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:479
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When using ldap_pwd_policy=shadow or ldap_account_expire_policy=shadow, this "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"parameter contains the name of an LDAP attribute corresponding to its "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> counterpart (account expiration date)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:489
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: shadowExpire"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:495
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_krb_last_pwd_change (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:498
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"an LDAP attribute storing the date and time of last password change in "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"kerberos."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:504
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: krbLastPwdChange"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:510
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_krb_password_expiration (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:513
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"an LDAP attribute storing the date and time when current password expires."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:519
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: krbPasswordExpiration"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:525
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ad_account_expires (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:528
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of an LDAP attribute storing the expiration time of the account."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:533
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: accountExpires"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:539
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_ad_user_account_control (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:542
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"of an LDAP attribute storing the user account control bit field."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:547
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: userAccountControl"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:553
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_ns_account_lock (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:556
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When using ldap_account_expire_policy=rhds or equivalent, this parameter "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"determines if access is allowed or not."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:561
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: nsAccountLock"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:567
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "ldap_user_nds_login_disabled (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:570
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines if "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"access is allowed or not."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:574 sssd-ldap.5.xml:588
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: loginDisabled"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:580
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "ldap_user_nds_login_expiration_time (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:583
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines until "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"which date access is granted."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:594
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "ldap_user_nds_login_allowed_time_map (string)"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:597
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines the "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"hours of a day in a week when access is granted."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:602
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "Default: loginAllowedTimeMap"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:608
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_principal (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:611
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The LDAP attribute that contains the user's Kerberos User Principal Name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"(UPN)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:615
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: krbPrincipalName"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:621
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:624
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Comma-separated list of LDAP attributes that SSSD would fetch along with the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"usual set of user attributes."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:629
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The list can either contain LDAP attribute names only, or colon-separated "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"tuples of SSSD cache attribute name and LDAP attribute name. In case only "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"LDAP attribute name is specified, the attribute is saved to the cache "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"verbatim. Using a custom SSSD attribute name might be required by "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"environments that configure several SSSD domains with different LDAP schemas."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:639
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that several attribute names are reserved by SSSD, notably the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>name</quote> attribute. SSSD would report an error if any of the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"reserved attribute names is used as an extra attribute name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:649
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs = telephoneNumber"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:652
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Save the <quote>telephoneNumber</quote> attribute from LDAP as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>telephoneNumber</quote> to the cache."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:656
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs = phone:telephoneNumber"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:659
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Save the <quote>telephoneNumber</quote> attribute from LDAP as <quote>phone</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> to the cache."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:669
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_ssh_public_key (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:672
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The LDAP attribute that contains the user's SSH public keys."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:676
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: sshPublicKey"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:682
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_force_upper_case_realm (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:685
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Some directory servers, for example Active Directory, might deliver the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"realm part of the UPN in lower case, which might cause the authentication to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fail. Set this option to a non-zero value if you want to use an upper-case "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"realm."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:698
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_enumeration_refresh_timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:701
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Specifies how many seconds SSSD has to wait before refreshing its cache of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"enumerated records."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:712
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_purge_cache_timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:715
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Determine how often to check the cache for inactive entries (such as groups "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"with no members and users who have never logged in) and remove them to save "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"space."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#: sssd-ldap.5.xml:721
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Setting this option to zero will disable the cache cleanup operation. Please "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"note that if enumeration is enabled, the cleanup task is required in order "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"to detect entries removed from the server and can't be disabled. By default, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the cleanup task will run every 3 hours with enumeration enabled."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:736
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_fullname (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:739
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the user's full name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:743 sssd-ldap.5.xml:850 sssd-ldap.5.xml:1095
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1169 sssd-ldap.5.xml:2210 sssd-ipa.5.xml:590
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: cn"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:749
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_member_of (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:752
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that lists the user's group memberships."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:756
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: memberOf"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:762
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_authorized_service (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:765
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If access_provider=ldap and ldap_access_order=authorized_service, SSSD will "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"use the presence of the authorizedService attribute in the user's LDAP entry "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to determine access privilege."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:772
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"An explicit deny (!svc) is resolved first. Second, SSSD searches for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"explicit allow (svc) and finally for allow_all (*)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:777
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>authorized_service</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_user_authorized_service option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:784
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: authorizedService"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:790
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "ldap_user_authorized_host (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:793
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"If access_provider=ldap and ldap_access_order=host, SSSD will use the "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"presence of the host attribute in the user's LDAP entry to determine access "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"privilege."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:799
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"An explicit deny (!host) is resolved first. Second, SSSD searches for "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"explicit allow (host) and finally for allow_all (*)."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:804
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>host</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_user_authorized_host option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:811
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "Default: host"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:817
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_user_certificate (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:820
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Name of the LDAP attribute containing the X509 certificate of the user."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:824
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: no set in the general case, userCertificate;binary for IPA"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:831
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "ldap_group_object_class (string)"
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:834
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The object class of a group entry in LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:837
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: posixGroup"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:843
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_group_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:846
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the group name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:856
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_group_gid_number (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:859
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the group's id."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:869
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_group_member (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:872
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that contains the names of the group's members."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:876
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: memberuid (rfc2307) / member (rfc2307bis)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:882
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_group_uuid (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:885
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:896
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_group_objectsid (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:899
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The LDAP attribute that contains the objectSID of an LDAP group object. This "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"is usually only necessary for ActiveDirectory servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:911
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_group_modify_timestamp (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:924
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_group_type (integer)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:927
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The LDAP attribute that contains an integer value indicating the type of the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"group and maybe other flags."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:932
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This attribute is currently only used by the AD provider to determine if a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"group is a domain local groups and has to be filtered out for trusted "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domains."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:938
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: groupType in the AD provider, othewise not set"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:945
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_group_external_member (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-ldap.5.xml:948
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The LDAP attribute that references group members that are defined in an "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"external domain. At the moment, only IPA's external members are supported."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:954
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: ipaExternalMember in the IPA provider, otherwise unset."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:961
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_group_nesting_level (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:964
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If ldap_schema is set to a schema format that supports nested groups (e.g. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"RFC2307bis), then this option controls how many levels of nesting SSSD will "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"follow. This option has no effect on the RFC2307 schema."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:971
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Note: This option specifies the guaranteed level of nested groups to be "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"processed for any lookup. However, nested groups beyond this limit "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<emphasis>may be</emphasis> returned if previous lookups already resolved "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the deeper nesting levels. Also, subsequent lookups for other groups may "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"enlarge the result set for original lookup if re-queried."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:980
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"If ldap_group_nesting_level is set to 0 then no nested groups are processed "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"at all. However, when connected to Active-Directory Server 2008 and later "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"using <quote>id_provider=ad</quote> it is furthermore required to disable "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"usage of Token-Groups by setting ldap_use_tokengroups to false in order to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"restrict group nesting."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:989
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 2"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:995
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_groups_use_matching_rule_in_chain"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:998
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option tells SSSD to take advantage of an Active Directory-specific "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"feature which may speed up group lookup operations on deployments with "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"complex or deep nested groups."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1004
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"In most common cases, it is best to leave this option disabled. It generally "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"only provides a performance increase on very complex nestings."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1009 sssd-ldap.5.xml:1036
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If this option is enabled, SSSD will use it if it detects that the server "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"supports it during initial connection. So \"True\" here essentially means "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"auto-detect\"."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1015 sssd-ldap.5.xml:1042
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Note: This feature is currently known to work only with Active Directory "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"2008 R1 and later. See <ulink url=\"http://msdn.microsoft.com/en-us/library/"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"windows/desktop/aa746475%28v=vs.85%29.aspx\"> MSDN(TM) documentation</ulink> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"for more details."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1027
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_initgroups_use_matching_rule_in_chain"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1030
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option tells SSSD to take advantage of an Active Directory-specific "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"feature which might speed up initgroups operations (most notably when "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"dealing with complex or deep nested groups)."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1057
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"This options enables or disables use of Token-Groups attribute when "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"performing initgroup for users from Active Directory Server 2008 and later."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1062
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: True for AD and IPA otherwise False."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1068
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_netgroup_object_class (string)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1071
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The object class of a netgroup entry in LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1074
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_object_class should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1078
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: nisNetgroup"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1084
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_netgroup_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1087
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that corresponds to the netgroup name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1091
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_name should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1101
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_netgroup_member (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1104
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The LDAP attribute that contains the names of the netgroup's members."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1108
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_member should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1112
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: memberNisNetgroup"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1118
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_netgroup_triple (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1121
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The LDAP attribute that contains the (host, user, domain) netgroup triples."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1125 sssd-ldap.5.xml:1141
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "This option is not available in IPA provider."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1128
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: nisNetgroupTriple"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1134
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_netgroup_modify_timestamp (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1150
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_object_class (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1153
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a service entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1156
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipService"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1162
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_name (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1165
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the name of service attributes and their "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"aliases."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1175
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_port (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1178
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that contains the port managed by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1182
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipServicePort"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1188
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_proto (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1191
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the protocols understood by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1195
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipServiceProtocol"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1201
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1206
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_search_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1209
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the timeout (in seconds) that ldap searches are allowed to run "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"before they are cancelled and cached results are returned (and offline mode "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"is entered)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1215
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note: this option is subject to change in future versions of the SSSD. It "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"will likely be replaced at some point by a series of timeouts for specific "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"lookup types."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1227
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_enumeration_search_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1230
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the timeout (in seconds) that ldap searches for user and group "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"enumerations are allowed to run before they are cancelled and cached results "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"are returned (and offline mode is entered)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1243
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_network_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1246
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the timeout (in seconds) after which the <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> following a <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> returns in case of no activity."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1269
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_opt_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1272
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies a timeout (in seconds) after which calls to synchronous LDAP APIs "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"will abort if no response is received. Also controls the timeout when "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"communicating with the KDC in case of SASL bind, the timeout of an LDAP bind "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"operation, password change extended operation and the StartTLS operation."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1287
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_connection_expire_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1290
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies a timeout (in seconds) that a connection to an LDAP server will be "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"maintained. After this time, the connection will be re-established. If used "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"in parallel with SASL/GSSAPI, the sooner of the two values (this value vs. "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"the TGT lifetime) will be used."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1298 sssd-ldap.5.xml:2367
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Default: 900 (15 minutes)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1304
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "ldap_page_size (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1307
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"Specify the number of records to retrieve from LDAP in a single request. "
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher"Some LDAP servers enforce a maximum limit per-request."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1312
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "Default: 1000"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1318
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_disable_paging (boolean)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1321
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Disable the LDAP paging control. This option should be used if the LDAP "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"server reports that it supports the LDAP paging control in its RootDSE but "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"it is not enabled or does not behave properly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1327
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Example: OpenLDAP servers with the paging control module installed on the "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"server but not enabled will report it in the RootDSE but be unable to use it."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1333
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Example: 389 DS has a bug where it can only support a one paging control at "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"a time on a single connection. On busy clients, this can result in some "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"requests being denied."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1345
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "ldap_disable_range_retrieval (boolean)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1348
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Disable Active Directory range retrieval."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1351
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Active Directory limits the number of members to be retrieved in a single "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"lookup using the MaxValRange policy (which defaults to 1500 members). If a "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"group contains more members, the reply would include an AD-specific range "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"extension. This option disables parsing of the range extension, therefore "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"large groups will appear as having no members."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1366
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_sasl_minssf (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1369
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When communicating with an LDAP server using SASL, specify the minimum "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"security level necessary to establish the connection. The values of this "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"option are defined by OpenLDAP."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1375
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: Use the system default (usually specified by ldap.conf)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1382
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid "ldap_deref_threshold (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1385
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Specify the number of group members that must be missing from the internal "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"cache in order to trigger a dereference lookup. If less members are missing, "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"they are looked up individually."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1391
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"You can turn off dereference lookups completely by setting the value to 0."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1395
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"A dereference lookup is a means of fetching all group members in a single "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"LDAP call. Different LDAP servers may implement different dereference "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"methods. The currently supported servers are 389/RHDS, OpenLDAP and Active "
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher"Directory."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1403
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"<emphasis>Note:</emphasis> If any of the search bases specifies a search "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"filter, then the dereference lookup performance enhancement will be disabled "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"regardless of this setting."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1416
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_reqcert (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1419
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Specifies what checks to perform on server certificates in a TLS session, if "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"any. It can be specified as one of the following values:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1425
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>never</emphasis> = The client will not request or check any server "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"certificate."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1429
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>allow</emphasis> = The server certificate is requested. If no "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"certificate is provided, the session proceeds normally. If a bad certificate "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"is provided, it will be ignored and the session proceeds normally."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1436
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>try</emphasis> = The server certificate is requested. If no "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"certificate is provided, the session proceeds normally. If a bad certificate "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"is provided, the session is immediately terminated."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1442
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>demand</emphasis> = The server certificate is requested. If no "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"certificate is provided, or a bad certificate is provided, the session is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"immediately terminated."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1448
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1452
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: hard"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1458
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_cacert (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1461
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the file that contains certificates for all of the Certificate "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Authorities that <command>sssd</command> will recognize."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1466 sssd-ldap.5.xml:1484 sssd-ldap.5.xml:1525
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Default: use OpenLDAP defaults, typically in <filename>/etc/openldap/ldap."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"conf</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1473
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_cacertdir (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1476
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the path of a directory that contains Certificate Authority "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"certificates in separate individual files. Typically the file names need to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"be the hash of the certificate followed by '.0'. If available, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>cacertdir_rehash</command> can be used to create the correct names."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1491
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_cert (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1494
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the file that contains the certificate for the client's key."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1504
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_key (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1507
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the file that contains the client's key."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1516
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_tls_cipher_suite (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1519
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Specifies acceptable cipher suites. Typically this is a colon separated "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum></citerefentry> for format."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1532
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_id_use_start_tls (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1535
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Specifies that the id_provider connection must also use <systemitem class="
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"\"protocol\">tls</systemitem> to protect the channel."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1545
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_id_mapping (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1548
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies that SSSD should attempt to map user and group IDs from the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_user_objectsid and ldap_group_objectsid attributes instead of relying "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"on ldap_user_uid_number and ldap_group_gid_number."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1554
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Currently this feature supports only ActiveDirectory objectSID mapping."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1564
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "ldap_min_id, ldap_max_id (interger)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1567
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"In contrast to the SID based ID mapping which is used if ldap_id_mapping is "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"set to true the allowed ID range for ldap_user_uid_number and "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"ldap_group_gid_number is unbound. In a setup with sub/trusted-domains this "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"might lead to ID collisions. To avoid collisions ldap_min_id and ldap_max_id "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"can be set to restrict the allowed range for the IDs which are read directly "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"from the server. Sub-domains can then pick other ranges to map IDs."
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1579
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "Default: not set (both options are set to 0)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1585
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "ldap_sasl_mech (string)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1588
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specify the SASL mechanism to use. Currently only GSSAPI is tested and "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"supported."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1598
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_sasl_authid (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1601
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specify the SASL authorization id to use. When GSSAPI is used, this "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"represents the Kerberos principal used for authentication to the directory. "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"This option can either contain the full principal (for example host/"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"myhost@EXAMPLE.COM) or just the principal name (for example host/myhost)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1609
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: host/hostname@REALM"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1615
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_sasl_realm (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1618
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Specify the SASL realm to use. When not specified, this option defaults to "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"the value of krb5_realm. If the ldap_sasl_authid contains the realm as "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"well, this option is ignored."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1624
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: the value of krb5_realm."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1630
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_sasl_canonicalize (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1633
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If set to true, the LDAP library would perform a reverse lookup to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"canonicalize the host name during a SASL bind."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1638
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: false;"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1644
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_krb5_keytab (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1647
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specify the keytab to use when using SASL/GSSAPI."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1650
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1656
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_krb5_init_creds (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1659
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Specifies that the id_provider should init Kerberos credentials (TGT). This "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"action is performed only if SASL is used and the mechanism selected is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"GSSAPI."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1671
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_krb5_ticket_lifetime (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1674
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the lifetime in seconds of the TGT if GSSAPI is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1678 sssd-ad.5.xml:859
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: 86400 (24 hours)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1684 sssd-krb5.5.xml:74
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "krb5_server, krb5_backup_server (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1687
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the comma-separated list of IP addresses or hostnames of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Kerberos servers to which SSSD should connect in the order of preference. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For more information on failover and server redundancy, see the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>FAILOVER</quote> section. An optional port number (preceded by a "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"colon) may be appended to the addresses or hostnames. If empty, service "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"discovery is enabled - for more information, refer to the <quote>SERVICE "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"DISCOVERY</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1699 sssd-krb5.5.xml:89
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When using service discovery for KDC or kpasswd servers, SSSD first searches "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"for DNS entries that specify _udp as the protocol and falls back to _tcp if "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"none are found."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1704 sssd-krb5.5.xml:94
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This option was named <quote>krb5_kdcip</quote> in earlier releases of SSSD. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"While the legacy name is recognized for the time being, users are advised to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"migrate their config files to use <quote>krb5_server</quote> instead."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1713 sssd-ipa.5.xml:415 sssd-krb5.5.xml:103
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_realm (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1716
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specify the Kerberos REALM (for SASL/GSSAPI auth)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1719
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1725 sssd-ipa.5.xml:430 sssd-krb5.5.xml:462
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "krb5_canonicalize (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1728
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host principal should be canonicalized when connecting to "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"LDAP server. This feature is available with MIT Kerberos >= 1.7"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1740 sssd-krb5.5.xml:477
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "krb5_use_kdcinfo (boolean)"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1743 sssd-krb5.5.xml:480
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"Specifies if the SSSD should instruct the Kerberos libraries what realm and "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"which KDCs to use. This option is on by default, if you disable it, you need "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"to configure the Kerberos library using the <citerefentry> "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> </"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"citerefentry> configuration file."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1754 sssd-krb5.5.xml:491
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"See the <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> manual page for more "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"information on the locator plugin."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1768
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_pwd_policy (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1771
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Select the policy to evaluate the password expiration on the client side. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The following values are allowed:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1776
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>none</emphasis> - No evaluation on the client side. This option "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"cannot disable server-side password policies."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1781
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<emphasis>shadow</emphasis> - Use <citerefentry><refentrytitle>shadow</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum></citerefentry> style attributes to "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"evaluate if the password has expired."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1787
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<emphasis>mit_kerberos</emphasis> - Use the attributes used by MIT Kerberos "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to determine if the password has expired. Use chpass_provider=krb5 to update "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"these attributes when the password is changed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1796
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: if a password policy is configured on server "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"side, it always takes precedence over policy set with this option."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1804
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_referrals (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1807
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies whether automatic referral chasing should be enabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1811
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that sssd only supports referral chasing when it is compiled "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"with OpenLDAP version 2.4.13 or higher."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1816
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Chasing referrals may incur a performance penalty in environments that use "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"them heavily, a notable example is Microsoft Active Directory. If your setup "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"does not in fact require the use of referrals, setting this option to false "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"might bring a noticeable performance improvement."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1830
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_dns_service_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1833
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Specifies the service name to use when service discovery is enabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1837
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: ldap"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1843
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_chpass_dns_service_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1846
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the service name to use to find an LDAP server which allows "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"password changes when service discovery is enabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1851
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set, i.e. service discovery is disabled"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1857
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "ldap_chpass_update_last_change (bool)"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1860
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Specifies whether to update the ldap_user_shadow_last_change attribute with "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"days since the Epoch after a password change operation."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1872
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_access_filter (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1875
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"If using access_provider = ldap and ldap_access_order = filter (default), "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"this option is mandatory. It specifies an LDAP search filter criteria that "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"must be met for the user to be granted access on this host. If "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"access_provider = ldap, ldap_access_order = filter and this option is not "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"set, it will result in all users being denied access. Use access_provider = "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permit to change this default behavior. Please note that this filter is "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"applied on the LDAP user entry only and thus filtering based on nested "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"groups may not work (e.g. memberOf attribute on AD entries points only to "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"direct parents). If filtering based on nested groups is required, please see "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<citerefentry> <refentrytitle>sssd-simple</refentrytitle><manvolnum>5</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manvolnum> </citerefentry>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1895
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Example:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1898
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"access_provider = ldap\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ldap_access_filter = (employeeType=admin)\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher" "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1902
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This example means that access to this host is restricted to users whose "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"employeeType attribute is set to \"admin\"."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1907
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Offline caching for this feature is limited to determining whether the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"user's last online login was granted access permission. If they were granted "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"access during their last login, they will continue to be granted access "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"while offline and vice-versa."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1915 sssd-ldap.5.xml:1972
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Empty"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1921
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_account_expire_policy (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1924
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"With this option a client side evaluation of access control attributes can "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"be enabled."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1928
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Please note that it is always recommended to use server side access control, "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"i.e. the LDAP server should deny the bind request with a suitable error code "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"even if the password is correct."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1935
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The following values are allowed:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1938
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"determine if the account is expired."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1943
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>ad</emphasis>: use the value of the 32bit field "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_ad_user_account_control and allow access if the second bit is not "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"set. If the attribute is missing access is granted. Also the expiration time "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"of the account is checked."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1950
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, <emphasis>389ds</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"emphasis>: use the value of ldap_ns_account_lock to check if access is "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"allowed or not."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1956
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>nds</emphasis>: the values of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled and "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_nds_login_expiration_time are used to check if access is allowed. "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"If both attributes are missing access is granted."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1965
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>expire</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_account_expire_policy option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1978
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_access_order (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1981
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Comma separated list of access control options. Allowed values are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1985
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>filter</emphasis>: use ldap_access_filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1988
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<emphasis>lockout</emphasis>: use account locking. If set, this option "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"and has value of '000001010000Z'. Please see the option ldap_pwdlockout_dn. "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Please note that 'access_provider = ldap' must be set for this feature to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"work."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:1998
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis> Please note that this option is superseded by the <quote>ppolicy</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"quote> option and might be removed in a future release. </emphasis>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2005
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis>ppolicy</emphasis>: use account locking. If set, this option "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"and has value of '000001010000Z' or represents any time in the past. The "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"value of the 'pwdAccountLockedTime' attribute must end with 'Z', which "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"denotes the UTC time zone. Other time zones are not currently supported and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"will result in \"access-denied\" when users attempt to log in. Please see "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"must be set for this feature to work."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2022
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2026
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_renew: </emphasis> These options are useful if users are "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"interested in being warned that password is about to expire and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"authentication is based on using a different method than passwords - for "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"example SSH keys."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2036
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The difference between these options is the action taken if user password is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"expired: pwd_expire_policy_reject - user is denied to log in, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_warn - user is still able to log in, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_renew - user is prompted to change his password "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"immediately."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2044
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note If user password is expired no explicit message is prompted by SSSD."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2048
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Please note that 'access_provider = ldap' must be set for this feature to "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"work. Also 'ldap_pwd_policy' must be set to an appropriate password policy."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2053
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>authorized_service</emphasis>: use the authorizedService attribute "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"to determine access"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2058
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>host</emphasis>: use the host attribute to determine access"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2062
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2065
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Please note that it is a configuration error if a value is used more than "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"once."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2072
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ldap_pwdlockout_dn (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2075
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This option specifies the DN of password policy entry on LDAP server. Please "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"note that absence of this option in sssd.conf in case of enabled account "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"lockout checking will yield access denied as ppolicy attributes on LDAP "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"server cannot be checked properly."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2083
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2086
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: cn=ppolicy,ou=policies,$ldap_search_base"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2092
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_deref (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2095
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies how alias dereferencing is done when performing a search. The "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"following options are allowed:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2100
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>never</emphasis>: Aliases are never dereferenced."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2104
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the base object, but not in locating the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2109
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>finding</emphasis>: Aliases are only dereferenced when locating "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2114
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>always</emphasis>: Aliases are dereferenced both in searching and "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"in locating the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2119
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"client libraries)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2127
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_rfc2307_fallback_to_local_users (boolean)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2130
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Allows to retain local users as members of an LDAP group for servers that "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"use the RFC2307 schema."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2134
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"In some environments where the RFC2307 schema is used, local users are made "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"members of LDAP groups by adding their names to the memberUid attribute. "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The self-consistency of the domain is compromised when this is done, so SSSD "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"would normally remove the \"missing\" users from the cached group "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"memberships as soon as nsswitch tries to fetch information about the user "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"via getpw*() or initgroups() calls."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2145
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"This option falls back to checking if local users are referenced, and caches "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"them so that later initgroups() calls will augment the local users with the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"additional LDAP groups."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2157 sssd-ifp.5.xml:136
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "enum_cache_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "wildcart_limit (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "enum_cache_timeout (numeriek)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2160
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies an upper limit on the number of entries that are downloaded during "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"a wildcard lookup."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2164
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "At the moment, only the InfoPipe responder supports wildcard lookups."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2168
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: 1000 (often the size of one page)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:51
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"All of the common configuration options that apply to SSSD domains also "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"apply to LDAP domains. Refer to the <quote>DOMAIN SECTIONS</quote> section "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"manvolnum> </citerefentry> manual page for full details. <placeholder type="
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"\"variablelist\" id=\"0\"/>"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2178
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "SUDO OPTIONS"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2180
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The detailed instructions for configuration of sudo_provider are in the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2191
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_object_class (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2194
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a sudo rule entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2197
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRole"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2203
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_name (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2206
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo rule name."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2216
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_command (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2219
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the command name."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2223
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoCommand"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2229
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_host (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2232
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the host name (or host IP address, "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"host IP network, or host netgroup)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2237
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoHost"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2243
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_user (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2246
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the user name (or UID, group name or "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"user's netgroup)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2250
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoUser"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2256
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_option (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2259
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo options."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2263
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoOption"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2269
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_runasuser (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2272
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the user name that commands may be "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"run as."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2276
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRunAsUser"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2282
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_runasgroup (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2285
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the group name or group GID that "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"commands may be run as."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2289
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRunAsGroup"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2295
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_notbefore (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2298
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the start date/time for when the sudo "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"rule is valid."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2302
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoNotBefore"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2308
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_notafter (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2311
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the expiration date/time, after which "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the sudo rule will no longer be valid."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2316
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoNotAfter"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2322
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_order (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2325
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the ordering index of the rule."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2329
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoOrder"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2335
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_full_refresh_interval (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2338
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds SSSD will wait between executing a full refresh of sudo "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"rules (which downloads all rules that are stored on the server)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2343
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"emphasis>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2348
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: 21600 (6 hours)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2354
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_smart_refresh_interval (integer)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2357
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds SSSD has to wait before executing a smart refresh of sudo "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"rules (which downloads all rules that have USN higher than the highest USN "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"of cached rules)."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2363
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If USN attributes are not supported by the server, the modifyTimestamp "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"attribute is used instead."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2373
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_use_host_filter (boolean)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2376
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If true, SSSD will download only rules that are applicable to this machine "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"(using the IPv4 or IPv6 host/network addresses and hostnames)."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2387
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_hostnames (string)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2390
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Space separated list of hostnames or fully qualified domain names that "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"should be used to filter the rules."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2395
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"If this option is empty, SSSD will try to discover the hostname and the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"fully qualified domain name automatically."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2400 sssd-ldap.5.xml:2423 sssd-ldap.5.xml:2441
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2459
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If <emphasis>ldap_sudo_use_host_filter</emphasis> is <emphasis>false</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"emphasis> then this option has no effect."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2405 sssd-ldap.5.xml:2428
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: not specified"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2411
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_ip (string)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2414
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Space separated list of IPv4 or IPv6 host/network addresses that should be "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"used to filter the rules."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2419
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If this option is empty, SSSD will try to discover the addresses "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"automatically."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2434
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_include_netgroups (boolean)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2437
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If true then SSSD will download every rule that contains a netgroup in "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"sudoHost attribute."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2452
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_include_regexp (boolean)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2455
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If true then SSSD will download every rule that contains a wildcard in "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"sudoHost attribute."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2471
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"This manual page only describes attribute name mapping. For detailed "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"explanation of sudo related attribute semantics, see <citerefentry> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"citerefentry>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2481
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "AUTOFS OPTIONS"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2483
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Some of the defaults for the parameters below are dependent on the LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"schema."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2489
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_autofs_map_master_name (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2492
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The name of the automount master map in LDAP."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2495
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: auto.master"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2502
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_map_object_class (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2505
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of an automount map entry in LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2508
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2516
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_map_name (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2519
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The name of an automount map entry in LDAP."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2522
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Default: nisMapName (rfc2307, autofs_provider=ad), otherwise automountMapName"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2530
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_object_class (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2533
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The object class of an automount entry in LDAP. The entry usually "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"corresponds to a mount point."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2538
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2546
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_key (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2549 sssd-ldap.5.xml:2564
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The key of an automount entry in LDAP. The entry usually corresponds to a "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"mount point."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2553
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2561
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_value (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2568
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"automountInformation"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:2487
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<placeholder type=\"variablelist\" id=\"3\"/> <placeholder type="
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\"variablelist\" id=\"4\"/> <placeholder type=\"variablelist\" id=\"5\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2579
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ADVANCED OPTIONS"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2586
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_netgroup_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2591
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_user_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2596
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ldap_group_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2601
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "<note>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2603
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"If the option <quote>ldap_use_tokengroups</quote> is enabled. The searches "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"against Active Directory will not be restricted and return all groups "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"memberships, even with no gid mapping. It is recommended to disable this "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"feature, if group names are not being displayed correctly."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2610
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "</note>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2612
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudo_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2617
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2581
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"These options are supported by LDAP domains, but they should be used with "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"caution. Please include them in your configuration only if you know what you "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"\"variablelist\" id=\"1\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2634
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The following example assumes that SSSD is correctly configured and LDAP is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"set to one of the domains in the <replaceable>[domains]</replaceable> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2640
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/LDAP]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_tls_reqcert = demand\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2639 sssd-ldap.5.xml:2657 sssd-simple.5.xml:139
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:725 sssd-ad.5.xml:973 sssd-sudo.5.xml:56 sssd-sudo.5.xml:98
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:573 include/ldap_id_mapping.xml:105
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<placeholder type=\"programlisting\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2651
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "LDAP ACCESS FILTER EXAMPLE"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2653
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The following example assumes that SSSD is correctly configured and to use "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"the ldap_access_order=lockout."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2658
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#, no-wrap
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/LDAP]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"access_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_access_order = lockout\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_tls_reqcert = demand\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2673 sssd_krb5_locator_plugin.8.xml:61
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-simple.5.xml:148 sssd-ad.5.xml:988 sssd.8.xml:195 sss_seed.8.xml:163
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "NOTES"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd-ldap.5.xml:2675
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The descriptions of some of the configuration options in this manual page "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are based on the <citerefentry> <refentrytitle>ldap.conf</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"distribution."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refentryinfo>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: pam_sss.8.xml:8 include/upstream.xml:2
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<productname>SSSD</productname> <orgname>The SSSD upstream - http://"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"fedorahosted.org/sssd</orgname>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: pam_sss.8.xml:13 pam_sss.8.xml:18
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "pam_sss"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: pam_sss.8.xml:19
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "PAM module for SSSD"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: pam_sss.8.xml:24
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>pam_sss.so</command> <arg choice='opt'> <replaceable>quiet</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>forward_pass</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>use_first_pass</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>use_authtok</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>retry=N</replaceable> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_unknown_user</replaceable> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_authinfo_unavail</replaceable> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"arg> <arg choice='opt'> <replaceable>domains=X</replaceable> </arg> <arg "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"choice='opt'> <replaceable>allow_missing_name</replaceable> </arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:57
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>pam_sss.so</command> is the PAM interface to the System Security "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Services daemon (SSSD). Errors and results are logged through "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<command>syslog(3)</command> with the LOG_AUTHPRIV facility."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:67
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>quiet</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:70
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Suppress log messages for unknown users."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:75
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>forward_pass</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:78
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If <option>forward_pass</option> is set the entered password is put on the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"stack for other PAM modules to use."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:85
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>use_first_pass</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:88
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The argument use_first_pass forces the module to use a previous stacked "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"modules password and will never prompt the user - if no password is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"available or the password is not appropriate, the user will be denied access."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:96
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>use_authtok</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:99
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"When password changing enforce the module to set the new password to the one "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"provided by a previously stacked password module."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:106
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>retry=N</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:109
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If specified the user is asked another N times for a password if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"authentication fails. Default is 0."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:111
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that this option might not work as expected if the application "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"calling PAM handles the user dialog on its own. A typical example is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sshd</command> with <option>PasswordAuthentication</option>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:120
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>ignore_unknown_user</option>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:123
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If this option is specified and the user does not exist, the PAM module will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"return PAM_IGNORE. This causes the PAM framework to ignore this module."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:130
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>ignore_authinfo_unavail</option>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:134
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies that the PAM module should return PAM_IGNORE if it cannot contact "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the SSSD daemon. This causes the PAM framework to ignore this module."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:141
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "<option>domains</option>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:145
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Allows the administrator to restrict the domains a particular PAM service is "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"allowed to authenticate against. The format is a comma-separated list of "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"SSSD domain names, as specified in the sssd.conf file."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:151
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"NOTE: Must be used in conjunction with the <quote>pam_trusted_users</quote> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"and <quote>pam_public_domains</quote> options. Please see the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"manvolnum> </citerefentry> manual page for more information on these two PAM "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"responder options."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:165
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>allow_missing_name</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:169
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The main purpose of this option is to let SSSD determine the user name based "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"on additional information, e.g. the certificate from a Smartcard."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:179
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"auth sufficient pam_sss.so allow_missing_name\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:174
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The current use case are login managers which can monitor a Smartcard reader "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for card events. In case a Smartcard is inserted the login manager will call "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"a PAM stack which includes a line like <placeholder type=\"programlisting\" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"id=\"0\"/> In this case SSSD will try to determine the user name based on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the content of the Smartcard, returns it to pam_sss which will finally put "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"it on the PAM stack."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:191
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "MODULE TYPES PROVIDED"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:192
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"All module types (<option>account</option>, <option>auth</option>, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>password</option> and <option>session</option>) are provided."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:198
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FILES"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:199
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If a password reset by root fails, because the corresponding SSSD provider "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"does not support password resets, an individual message can be displayed. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This message can e.g. contain instructions about how to reset a password."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:204
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The message is read from the file <filename>pam_sss_pw_reset_message.LOC</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"filename> where LOC stands for a locale string returned by <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry>. If there is no matching file the content of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<filename>pam_sss_pw_reset_message.txt</filename> is displayed. Root must be "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the owner of the files and only root may have read and write permissions "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"while all other users must have only read permissions."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:214
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"These files are searched in the directory <filename>/etc/sssd/customize/"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"DOMAIN_NAME/</filename>. If no matching file is present a generic message is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"displayed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd_krb5_locator_plugin"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd_krb5_locator_plugin.8.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Kerberos locator plugin"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:22
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The Kerberos locator plugin <command>sssd_krb5_locator_plugin</command> is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"used by the Kerberos provider of <citerefentry> <refentrytitle>sssd</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to tell the Kerberos "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"libraries what Realm and which KDC to use. Typically this is done in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> which is always read by the Kerberos libraries. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"To simplify the configuration the Realm and the KDC can be defined in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> as described in <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:48
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"</citerefentry> puts the Realm and the name or IP address of the KDC into "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the environment variables SSSD_KRB5_REALM and SSSD_KRB5_KDC respectively. "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"When <command>sssd_krb5_locator_plugin</command> is called by the kerberos "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"libraries it reads and evaluates these variables and returns them to the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"libraries."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:63
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Not all Kerberos implementations support the use of plugins. If "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sssd_krb5_locator_plugin</command> is not available on your system "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"you have to edit /etc/krb5.conf to reflect your Kerberos setup."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd_krb5_locator_plugin.8.xml:69
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"debug messages will be sent to stderr."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:10 sssd-simple.5.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-simple"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:17
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "the configuration file for SSSD's 'simple' access-control provider"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:24
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of the simple access-control "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"provider for <citerefentry> <refentrytitle>sssd</refentrytitle> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<manvolnum>8</manvolnum> </citerefentry>. For a detailed syntax reference, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"refer to the <quote>FILE FORMAT</quote> section of the <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> manual page."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:38
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The simple access provider grants or denies access based on an access or "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"deny list of user or group names. The following rules apply:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:43
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "If all lists are empty, access is granted"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:47
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If any list is provided, the order of evaluation is allow,deny. This means "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"that any matching deny rule will supersede any matched allow rule."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:54
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If either or both \"allow\" lists are provided, all users are denied unless "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"they appear in the list."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:60
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If only \"deny\" lists are provided, all users are granted access unless "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"they appear in the list."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:78
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "simple_allow_users (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:81
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Comma separated list of users who are allowed to log in."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:88
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "simple_deny_users (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:91
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Comma separated list of users who are explicitly denied access."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:97
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "simple_allow_groups (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:100
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Comma separated list of groups that are allowed to log in. This applies only "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"to groups within this SSSD domain. Local groups are not evaluated."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:108
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "simple_deny_groups (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:111
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Comma separated list of groups that are explicitly denied access. This "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"applies only to groups within this SSSD domain. Local groups are not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"evaluated."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-simple.5.xml:70 sssd-ipa.5.xml:71 sssd-ad.5.xml:90
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Refer to the section <quote>DOMAIN SECTIONS</quote> of the <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> manual page for details on the configuration of an SSSD "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"domain. <placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-simple.5.xml:120
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Specifying no values for any of the lists is equivalent to skipping it "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"entirely. Beware of this while generating parameters for the simple provider "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"using automated scripts."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:125
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that it is an configuration error if both, simple_allow_users "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"and simple_deny_users, are defined."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:133
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The following example assumes that SSSD is correctly configured and example."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This examples shows only the simple access provider-specific options."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:140
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/example.com]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"access_provider = simple\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"simple_allow_users = user1, user2\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sssd-simple.5.xml:150
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The complete group membership hierarchy is resolved before the access check, "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"thus even nested groups can be included in the access lists. Please be "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"aware that the <quote>ldap_group_nesting_level</quote> option may impact the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"results and should be set to a sufficient value. (<citerefentry> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"citerefentry>) option."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-ipa"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ipa.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD IPA provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:23
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of the IPA provider for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:36
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The IPA provider is a back end used to connect to an IPA server. (Refer to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the freeipa.org web site for information about IPA servers.) This provider "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"requires that the machine be joined to the IPA domain; configuration is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"almost entirely self-discovered and obtained directly from the server."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-ipa.5.xml:43
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The IPA provider accepts the same options used by the <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> identity provider and the <citerefentry> <refentrytitle>sssd-"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> authentication "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider with some exceptions described below."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd-ipa.5.xml:55
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"However, it is neither necessary nor recommended to set these options. IPA "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider can also be used as an access and chpass provider. As an access "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider it uses HBAC (host-based access control) rules. Please refer to "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"freeipa.org for more information about HBAC. No configuration of access "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider is required on the client side."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:62
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The IPA provider will use the PAC responder if the Kerberos tickets of users "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"from trusted realms contain a PAC. To make configuration easier the PAC "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"responder is started automatically if the IPA ID provider is configured."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:78
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_domain (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:81
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Specifies the name of the IPA domain. This is optional. If not provided, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the configuration domain name is used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:89
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ipa_server, ipa_backup_server (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:92
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The comma-separated list of IP addresses or hostnames of the IPA servers to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"which SSSD should connect in the order of preference. For more information "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"on failover and server redundancy, see the <quote>FAILOVER</quote> section. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This is optional if autodiscovery is enabled. For more information on "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:105
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_hostname (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:108
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Optional. May be set on machines where the hostname(5) does not reflect the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"fully qualified name used in the IPA domain to identify this host."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:116 sssd-ad.5.xml:790
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_update (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:119
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Optional. This option tells SSSD to automatically update the DNS server "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"built into FreeIPA with the IP address of this client. The update is secured "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"using GSS-TSIG. The IP address of the IPA LDAP connection is used for the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"updates, if it is not otherwise specified by using the <quote>dyndns_iface</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"quote> option."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:128 sssd-ad.5.xml:804
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the default Kerberos realm must be set properly in /etc/krb5.conf"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:133
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_update</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_update</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:145 sssd-ad.5.xml:815
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_ttl (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:148 sssd-ad.5.xml:818
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The TTL to apply to the client DNS record when updating it. If "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"dyndns_update is false this has no effect. This will override the TTL "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"serverside if set by an administrator."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:153
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_ttl</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_ttl</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:159
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 1200 (seconds)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:165 sssd-ad.5.xml:829
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_iface (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:168 sssd-ad.5.xml:832
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Optional. Applicable only when dyndns_update is true. Choose the interface "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"or a list of interfaces whose IP addresses should be used for dynamic DNS "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"updates. Special value <quote>*</quote> implies that IPs from all interfaces "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"should be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:175
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_iface</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:181
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for IPA LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"connection"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:185 sssd-ad.5.xml:843
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Example: dyndns_iface = em1, vnet1, vnet2"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:191
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "ipa_enable_dns_sites (boolean)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:194 sssd-ad.5.xml:160
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Enables DNS sites - location based service discovery."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:198
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"If true and service discovery (see Service Discovery paragraph at the bottom "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"of the man page) is enabled, then the SSSD will first attempt location "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"based discovery using a query that contains \"_location.hostname.example.com"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"\" and then fall back to traditional SRV discovery. If the location based "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"discovery succeeds, the IPA servers located with the location based "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"discovery are treated as primary servers and the IPA servers located using "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the traditional SRV discovery are used as back up servers"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:217 sssd-ad.5.xml:849
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_refresh_interval (integer)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:220 sssd-ad.5.xml:852
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"How often should the back end perform periodic DNS update in addition to the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"automatic update performed when the back end goes online. This option is "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"optional and applicable only when dyndns_update is true."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:233 sssd-ad.5.xml:865
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_update_ptr (bool)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:236 sssd-ad.5.xml:868
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Whether the PTR record should also be explicitly updated when updating the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"client's DNS records. Applicable only when dyndns_update is true."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:241
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"This option should be False in most IPA deployments as the IPA server "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"generates the PTR records automatically when forward records are changed."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:247
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: False (disabled)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:253 sssd-ad.5.xml:879
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_force_tcp (bool)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:256 sssd-ad.5.xml:882
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Whether the nsupdate utility should default to using TCP for communicating "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"with the DNS server."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:260 sssd-ad.5.xml:886
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: False (let nsupdate choose the protocol)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:266 sssd-ad.5.xml:892
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_server (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:269 sssd-ad.5.xml:895
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The DNS server to use when performing a DNS update. In most setups, it's "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"recommended to leave this option unset."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:274 sssd-ad.5.xml:900
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Setting this option makes sense for environments where the DNS server is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"different from the identity server."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:279 sssd-ad.5.xml:905
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Please note that this option will be only used in fallback attempt when "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"previous attempt using autodetected settings failed."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:284 sssd-ad.5.xml:910
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: None (let nsupdate choose the server)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:290
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "ipa_hbac_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:293
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid "Optional. Use the given string as search base for HBAC related objects."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:297
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Use base DN"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:303
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ipa_host_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:306
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Optional. Use the given string as search base for host objects."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:310 sssd-ipa.5.xml:329 sssd-ipa.5.xml:348 sssd-ipa.5.xml:367
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:386
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"See <quote>ldap_search_base</quote> for information about configuring "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"multiple search bases."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:315 sssd-ipa.5.xml:334 include/ldap_search_bases.xml:27
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: the value of <emphasis>ldap_search_base</emphasis>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:322
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ipa_selinux_search_base (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:325
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Optional. Use the given string as search base for SELinux user maps."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:341
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ipa_subdomains_search_base (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:344
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Optional. Use the given string as search base for trusted domains."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:353
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:360
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ipa_master_domain_search_base (string)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:363
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Optional. Use the given string as search base for master domain object."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:372
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:379
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_views_search_base (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:382
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Optional. Use the given string as search base for views containers."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:391
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:398 sssd-krb5.5.xml:254
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "krb5_validate (boolean)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:401
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Verify with the help of krb5_keytab that the TGT obtained has not been "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"spoofed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:408 sssd-ad.5.xml:931
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Note that this default differs from the traditional Kerberos provider back "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"end."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:418
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The name of the Kerberos realm. This is optional and defaults to the value "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"of <quote>ipa_domain</quote>."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:422
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The name of the Kerberos realm has a special meaning in IPA - it is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"converted into the base DN to use for performing LDAP operations."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgstr ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:433
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host and user principal should be canonicalized when "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"connecting to IPA LDAP and also for AS requests. This feature is available "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"with MIT Kerberos >= 1.7"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:446 sssd-krb5.5.xml:416
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "krb5_use_fast (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:449 sssd-krb5.5.xml:419
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Enables flexible authentication secure tunneling (FAST) for Kerberos pre-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"authentication. The following options are supported:"
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:454
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>never</emphasis> use FAST."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:457
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"continue the authentication without it. This is equivalent to not setting "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"this option at all."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:463 sssd-krb5.5.xml:433
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>demand</emphasis> to use FAST. The authentication fails if the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"server does not require fast."
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallaghermsgstr ""
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher
9643e7da1a54a9edb2360ab8f855664a8b4397caStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:468
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: try"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:471 sssd-krb5.5.xml:444
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: SSSD supports FAST only with MIT Kerberos version 1.8 and later. If "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD is used with an older version of MIT Kerberos, using this option is a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"configuration error."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:480 sssd-ad.5.xml:938
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "krb5_confd_path (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:483 sssd-ad.5.xml:941
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Absolute path of a directory where SSSD should place Kerberos configuration "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"snippets."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:487 sssd-ad.5.xml:945
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"To disable the creation of the configuration snippets set the parameter to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"'none'."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:491 sssd-ad.5.xml:949
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:498
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_hbac_refresh (integer)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:501
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The amount of time between lookups of the HBAC rules against the IPA server. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This will reduce the latency and load on the IPA server if there are many "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"access-control requests made in a short period."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ipa.5.xml:508 sssd-ipa.5.xml:524 sssd-ad.5.xml:355
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 5 (seconds)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:514
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_hbac_selinux (integer)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:517
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The amount of time between lookups of the SELinux maps against the IPA "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"server. This will reduce the latency and load on the IPA server if there are "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"many user login requests made in a short period."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:530
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_server_mode (boolean)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:533
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "This option should only be set by the IPA installer."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:537
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The option denotes that the SSSD is running on IPA server and should perform "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"lookups of users and groups from trusted domains differently."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:548
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_automount_location (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:551
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The automounter location this IPA client will be using"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:554
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: The location named \"default\""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:562
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "VIEWS AND OVERRIDES"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:571
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_view_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:574
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Objectclass of the view container."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:577
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: nsContainer"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:583
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_view_name (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:586
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Name of the attribute holding the name of the view."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:596
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_overide_object_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:599
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Objectclass of the override objects."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:602
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaOverrideAnchor"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:608
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_anchor_uuid (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:611
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the attribute containing the reference to the original object in a "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"remote domain."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:615
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaAnchorUUID"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:621
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_user_override_object_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:624
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the objectclass for user overrides. It is used to determine if the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"found override object is related to a user or a group."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:629
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "User overrides can contain attributes given by"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:632
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_name"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:635
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_uid_number"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:638
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_gid_number"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:641
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_gecos"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:644
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_home_directory"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:647
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_shell"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:650
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_user_ssh_public_key"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:655
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaUserOverride"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:661
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_group_override_object_class (string)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:664
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the objectclass for group overrides. It is used to determine if the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"found override object is related to a user or a group."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:669
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Group overrides can contain attributes given by"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:672
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_group_name"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:675
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_group_gid_number"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:680
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaGroupOverride"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:564
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"SSSD can handle views and overrides which are offered by FreeIPA 4.1 and "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"later version. Since all paths and objectclasses are fixed on the server "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"side there is basically no need to configure anything. For completeness the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"related options are listed here with their default values. <placeholder "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"type=\"variablelist\" id=\"0\"/>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:690
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "SUBDOMAINS PROVIDER"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:692
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The IPA subdomains provider behaves slightly differently if it is configured "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"explicitly or implicitly."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:696
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If the option 'subdomains_provider = ipa' is found in the domain section of "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"sssd.conf, the IPA subdomains provider is configured explicitly, and all "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"subdomain requests are sent to the IPA server if necessary."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:702
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If the option 'subdomains_provider' is not set in the domain section of sssd."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"conf but there is the option 'id_provider = ipa', the IPA subdomains "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"provider is configured implicitly. In this case, if a subdomain request "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"fails and indicates that the server does not support subdomains, i.e. is not "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"configured for trusts, the IPA subdomains provider is disabled. After an "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"hour or after the IPA provider goes online, the subdomains provider is "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"enabled again."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:719
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The following example assumes that SSSD is correctly configured and example."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"This examples shows only the ipa provider-specific options."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:726
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/example.com]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ipa\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ipa_server = ipaserver.example.com\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ipa_hostname = myhost.example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:10 sssd-ad.5.xml:16
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "sssd-ad"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ad.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD Active Directory provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:23
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This manual page describes the configuration of the AD provider for "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:36
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider is a back end used to connect to an Active Directory server. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This provider requires that the machine be joined to the AD domain and a "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"keytab is available."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:41
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider supports connecting to Active Directory 2008 R2 or later. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Earlier versions may work, but are unsupported."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:45
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The AD provider can be used to get user information and authenticate users "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from trusted domains. Currently only trusted domains in the same forest are "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"recognized. In addition servers from trusted domains are always auto-"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"discovered."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:51
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider accepts the same options used by the <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry> identity provider and the <citerefentry> <refentrytitle>sssd-"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> authentication "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"provider with some exceptions described below."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:63
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"However, it is neither necessary nor recommended to set these options. The "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"AD provider can also be used as an access, chpass, sudo and autofs provider. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"No configuration of the access provider is required on the client side."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:75
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_id_mapping = False\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek" "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:69
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"By default, the AD provider will map UID and GID values from the objectSID "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"parameter in Active Directory. For details on this, see the <quote>ID "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"MAPPING</quote> section below. If you want to disable ID mapping and instead "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"rely on POSIX attributes defined in Active Directory, you should set "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/> In order to retrieve users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"and groups using POSIX attributes from trusted domains, the AD administrator "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must make sure that the POSIX attributes are replicated to the Global "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Catalog."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:82
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Users, groups and other entities served by SSSD are always treated as case-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"insensitive in the AD provider for compatibility with Active Directory's "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"LDAP implementation."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:97
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ad_domain (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:100
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Specifies the name of the Active Directory domain. This is optional. If not "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"provided, the configuration domain name is used."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:105
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"For proper operation, this option should be specified as the lower-case "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"version of the long version of the Active Directory domain."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:110
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The short domain name (also known as the NetBIOS or the flat name) is "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"autodetected by the SSSD."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:117
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_server, ad_backup_server (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:120
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The comma-separated list of hostnames of the AD servers to which SSSD should "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"connect in order of preference. For more information on failover and server "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"redundancy, see the <quote>FAILOVER</quote> section."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:127
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This is optional if autodiscovery is enabled. For more information on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ad.5.xml:132
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Trusted domains will always auto-discover servers even if the primary "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"server is explicitly defined in the ad_server option."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:140
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_hostname (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:143
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Optional. May be set on machines where the hostname(5) does not reflect the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fully qualified name used in the Active Directory domain to identify this "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"host."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:149
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This field is used to determine the host principal in use in the keytab. It "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must match the hostname for which the keytab was issued."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:157
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_enable_dns_sites (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:164
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If true and service discovery (see Service Discovery paragraph at the bottom "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"of the man page) is enabled, the SSSD will first attempt to discover the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Active Directory server to connect to using the Active Directory Site "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Discovery and fall back to the DNS SRV records if no AD site is found. The "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"DNS SRV configuration, including the discovery domain, is used during site "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"discovery as well."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:180
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_access_filter (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:183
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option specifies LDAP access control filter that the user must match in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"order to be allowed access. Please note that the <quote>access_provider</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> option must be explicitly set to <quote>ad</quote> in order for this "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"option to have an effect."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:191
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The option also supports specifying different filters per domain or forest. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This extended filter would consist of: <quote>KEYWORD:NAME:FILTER</quote>. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The keyword can be either <quote>DOM</quote>, <quote>FOREST</quote> or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"missing."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:199
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If the keyword equals to <quote>DOM</quote> or is missing, then <quote>NAME</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> specifies the domain or subdomain the filter applies to. If the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"keyword equals to <quote>FOREST</quote>, then the filter equals to all "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domains from the forest specified by <quote>NAME</quote>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:207
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Multiple filters can be separated with the <quote>?</quote> character, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"similarly to how search bases work."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:212
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The most specific match is always used. For example, if the option specified "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"filter for a domain the user is a member of and a global filter, the per-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain filter would be applied. If there are more matches with the same "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"specification, the first one is used."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:223
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#, no-wrap
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on domain called dom1 only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on domain called dom2 only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on forest called EXAMPLE.COM only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:233 sssd-ad.5.xml:247
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: Not set"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:239
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ad_site (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:242
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Specify AD site to which client should try to connect. If this option is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"not provided, the AD site will be auto-discovered."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:253
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_enable_gc (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:256
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"By default, the SSSD connects to the Global Catalog first to retrieve users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"from trusted domains and uses the LDAP port to retrieve group memberships or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"as a fallback. Disabling this option makes the SSSD only connect to the LDAP "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"port of the current AD server."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:264
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that disabling Global Catalog support does not disable "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"retrieving users from trusted domains. The SSSD would connect to the LDAP "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"port of trusted domains instead. However, Global Catalog must be used in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"order to resolve cross-domain group memberships."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:278
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_gpo_access_control (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:281
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option specifies the operation mode for GPO-based access control "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"functionality: whether it operates in disabled mode, enforcing mode, or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permissive mode. Please note that the <quote>access_provider</quote> option "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must be explicitly set to <quote>ad</quote> in order for this option to have "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"an effect."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:290
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"GPO-based access control functionality uses GPO policy settings to determine "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"whether or not a particular user is allowed to logon to a particular host."
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:296
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: If the operation mode is set to enforcing, it is possible that users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that were previously allowed logon access will now be denied logon access "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"(as dictated by the GPO policy settings). In order to facilitate a smooth "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"transition for administrators, a permissive mode is available that will not "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"enforce the access control rules, but will evaluate them and will output a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"syslog message if access would have been denied. By examining the logs, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"administrators can then make the necessary changes before setting the mode "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"to enforcing."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:309
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "There are three supported values for this option:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:313
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"disabled: GPO-based access control rules are neither evaluated nor enforced."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:319
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "enforcing: GPO-based access control rules are evaluated and enforced."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:325
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permissive: GPO-based access control rules are evaluated, but not enforced. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Instead, a syslog message will be emitted indicating that the user would "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"have been denied access if this option's value were set to enforcing."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:336
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: permissive"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:339
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: enforcing"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:345
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_cache_timeout (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:348
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The amount of time between lookups of GPO policy files against the AD "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"server. This will reduce the latency and load on the AD server if there are "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"many access-control requests made in a short period."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:361
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_interactive (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:364
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the InteractiveLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyInteractiveLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:370
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on locally\" and \"Deny log on locally\"."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:384
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_interactive = +my_pam_service, -login\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:375
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>login</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:388 sssd-ad.5.xml:484 sssd-ad.5.xml:530 sssd-ad.5.xml:575
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:641
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: the default set of PAM service names includes:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:392
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "login"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:397
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "su"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:402
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "su-l"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:407
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-fingerprint"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:412
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-password"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:417
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-smartcard"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:422
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "kdm"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:427
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "lightdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:432
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "lxdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:437
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "sddm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:442
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "unity"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:447
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "xdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:456
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_remote_interactive (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:459
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the RemoteInteractiveLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyRemoteInteractiveLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:465
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"log on through Remote Desktop Services\" and \"Deny log on through Remote "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Desktop Services\"."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:480
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:471
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>sshd</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:488
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sshd"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:493
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "cockpit"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:502
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_network (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:505
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the NetworkLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyNetworkLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:511
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Access "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"this computer from the network\" and \"Deny access to this computer from the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"network\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:526
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_network = +my_pam_service, -ftp\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:517
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>ftp</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:534
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ftp"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:539
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "samba"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:548
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_batch (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:551
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the BatchLogonRight and DenyBatchLogonRight "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:557
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on as a batch job\" and \"Deny log on as a batch job\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:571
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_batch = +my_pam_service, -crond\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:562
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>crond</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:579
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "crond"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:588
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_service (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:591
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the ServiceLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyServiceLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:597
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on as a service\" and \"Deny log on as a service\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:610
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_service = +my_pam_service\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:602 sssd-ad.5.xml:677
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add a PAM service name to the default set by using <quote>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"+service_name</quote>. Since the default set is empty, it is not possible "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"to remove a PAM service name from the default set. For example, in order to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"add a custom pam service name (e.g. <quote>my_pam_service</quote>), you "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"would use the following configuration: <placeholder type=\"programlisting\" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:620
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_permit (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:623
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always granted, regardless of any GPO Logon Rights."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:637
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_permit = +my_pam_service, -sudo\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:628
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for unconditionally permitted "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access (e.g. <quote>sudo</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:645
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "polkit-1"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:650
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sudo"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:655
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sudo-i"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:660
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "systemd-user"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:669
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_deny (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:672
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always denied, regardless of any GPO Logon Rights."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:685
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_deny = +my_pam_service\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:695
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_default_right (string)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:698
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This option defines how access control is evaluated for PAM service names "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"that are not explicitly listed in one of the ad_gpo_map_* options. This "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"option can be set in two different manners. First, this option can be set to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"use a default logon right. For example, if this option is set to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"'interactive', it means that unmapped PAM service names will be processed "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"based on the InteractiveLogonRight and DenyInteractiveLogonRight policy "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"settings. Alternatively, this option can be set to either always permit or "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always deny access for unmapped PAM service names."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:711
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Supported values for this option include:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:715
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "interactive"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:720
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "remote_interactive"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:725
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "network"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:730
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "batch"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:735
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "service"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:740
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "permit"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:745
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "deny"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:751
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: deny"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:757
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_maximum_machine_account_password_age (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:760
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD will check once a day if the machine account password is older than the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"given age in days and try to renew it. A value of 0 will disable the renewal "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"attempt."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:766
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "Default: 3"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 30 days"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "Standaard: 3"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:772
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_machine_account_password_renewal_opts (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:775
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option should only be used to test the machine account renewal task. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The option expect 2 integers seperated by a colon (':'). The first integer "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"defines the interval in seconds how often the task is run. The second "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"specifies the inital timeout in seconds before the task is run for the first "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"time after startup."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:784
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 86400:750 (24h and 15m)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:793
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Optional. This option tells SSSD to automatically update the Active "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Directory DNS server with the IP address of this client. The update is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"secured using GSS-TSIG. As a consequence, the Active Directory administrator "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"only needs to allow secure updates for the DNS zone. The IP address of the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"AD LDAP connection is used for the updates, if it is not otherwise specified "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"by using the <quote>dyndns_iface</quote> option."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:823
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: 3600 (seconds)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:839
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for AD LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"connection"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:873 sss_rpcidmapd.5.xml:76
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: True"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:919 sssd-krb5.5.xml:505
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "krb5_use_enterprise_principal (boolean)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:922 sssd-krb5.5.xml:508
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Specifies if the user principal should be treated as enterprise principal. "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"See section 5 of RFC 6806 for more details about enterprise principals."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:967
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The following example assumes that SSSD is correctly configured and example."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This example shows only the AD provider-specific options."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:974
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#, no-wrap
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"[domain/EXAMPLE]\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"id_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"auth_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"access_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"chpass_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_server = dc1.example.com\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_hostname = client.example.com\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_domain = example.com\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:994
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#, no-wrap
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"access_provider = ldap\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_access_order = expire\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_account_expire_policy = ad\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:990
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The AD access control provider checks if the account is expired. It has the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"same effect as the following configuration of the LDAP provider: "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:1000
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"However, unless the <quote>ad</quote> access control provider is explicitly "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"configured, the default access provider is <quote>permit</quote>. Please "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"note that if you configure an access provider other than <quote>ad</quote>, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"you need to set all the connection parameters (such as LDAP URIs and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"encryption details) manually."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:1008
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"attribute mapping (nisMap, nisObject, ...) is used, because these attributes "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are included in the default Active Directory schema."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sssd-sudo"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-sudo.5.xml:17
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Configuring sudo with the SSSD back end"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:23
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This manual page describes how to configure <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:36
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Configuring sudo to cooperate with SSSD"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:38
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"To enable SSSD as a source for sudo rules, add <emphasis>sss</emphasis> to "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"the <emphasis>sudoers</emphasis> entry in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:47
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"For example, to configure sudo to first lookup rules in the standard "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<citerefentry> <refentrytitle>sudoers</refentrytitle> <manvolnum>5</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"manvolnum> </citerefentry> file (which should contain rules that apply to "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"local users) and then in SSSD, the nsswitch.conf file should contain the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"following line:"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:57
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sudoers: files sss\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:61
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"More information about configuring the sudoers search order from the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"nsswitch.conf file as well as information about the LDAP schema that is used "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"to store sudo rules in the directory can be found in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:70
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: in order to use netgroups or IPA hostgroups in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"sudo rules, you also need to correctly set <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>nisdomainname</refentrytitle> <manvolnum>1</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> to your NIS domain name (which equals to IPA domain name when "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"using hostgroups)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:82
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Configuring SSSD to fetch sudo rules"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:84
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"All configuration that is needed on SSSD side is to extend the list of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>services</emphasis> with \"sudo\" in [sssd] section of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry>. To speed up the LDAP lookups, you can also set "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"search base for sudo rules using <emphasis>ldap_sudo_search_base</emphasis> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"option."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:94
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The following example shows how to configure SSSD to download sudo rules "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"from an LDAP server."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:99
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"[sssd]\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"config_file_version = 2\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"services = nss, pam, sudo\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"domains = EXAMPLE\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"[domain/EXAMPLE]\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"id_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"sudo_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_uri = ldap://example.com\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:112
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"When the SSSD is configured to use IPA as the ID provider, the sudo provider "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is automatically enabled. The sudo search base is configured to use the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"compat tree (ou=sudoers,$DC)."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:119
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "The SUDO rule caching mechanism"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:121
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The biggest challenge, when developing sudo support in SSSD, was to ensure "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"that running sudo with SSSD as the data source provides the same user "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"experience and is as fast as sudo but keeps providing the most current set "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"of rules as possible. To satisfy these requirements, SSSD uses three kinds "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"of updates. They are referred to as full refresh, smart refresh and rules "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refresh."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:129
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>smart refresh</emphasis> periodically downloads rules that are "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"new or were modified after the last update. Its primary goal is to keep the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"database growing by fetching only small increments that do not generate "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"large amounts of network traffic."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:135
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>full refresh</emphasis> simply deletes all sudo rules stored "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"in the cache and replaces them with all rules that are stored on the server. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This is used to keep the cache consistent by removing every rule which was "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"deleted from the server. However, full refresh may produce a lot of traffic "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"and thus it should be run only occasionally depending on the size and "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"stability of the sudo rules."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:143
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>rules refresh</emphasis> ensures that we do not grant the user "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"more permission than defined. It is triggered each time the user runs sudo. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Rules refresh will find all rules that apply to this user, check their "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"expiration time and redownload them if expired. In the case that any of "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"these rules are missing on the server, the SSSD will do an out of band full "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refresh because more rules (that apply to other users) may have been deleted."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:152
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"If enabled, SSSD will store only rules that can be applied to this machine. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This means rules that contain one of the following values in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>sudoHost</emphasis> attribute:"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:159
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "keyword ALL"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:164
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "wildcard"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:169
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "netgroup (in the form \"+netgroup\")"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:174
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "hostname or fully qualified domain name of this machine"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:179
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "one of the IP addresses of this machine"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:184
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "one of the IP addresses of the network (in the form \"address/mask\")"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:190
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"There are many configuration options that can be used to adjust the "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"behavior. Please refer to \"ldap_sudo_*\" in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry> and \"sudo_*\" in <citerefentry> <refentrytitle>sssd.conf</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:10 sssd.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "System Security Services Daemon"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sssd</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:31
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>SSSD</command> provides a set of daemons to manage access to remote "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"directories and authentication mechanisms. It provides an NSS and PAM "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"interface toward the system and a pluggable backend system to connect to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"multiple different account sources as well as D-Bus interface. It is also "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the basis to provide client auditing and policy services for projects like "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"FreeIPA. It provides a more robust database to store local users as well as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"extended user data."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd.8.xml:46
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:53
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:57
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:60
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:69
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:73
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:76
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>0</emphasis>: Disable microseconds in timestamp"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:85
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-f</option>,<option>--debug-to-files</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:89
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Send the debug output to files instead of stderr. By default, the log files "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"are stored in <filename>/var/log/sssd</filename> and there are separate log "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"files for every SSSD service and domain."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:97
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-D</option>,<option>--daemon</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:101
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Become a daemon after starting up."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.8.xml:107 sss_seed.8.xml:136
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-i</option>,<option>--interactive</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:111
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Run in the foreground, don't become a daemon."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sssd.8.xml:117 sss_debuglevel.8.xml:42
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-c</option>,<option>--config</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sssd.8.xml:121 sss_debuglevel.8.xml:46
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Specify a non-default config file. The default is <filename>/etc/sssd/sssd."
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"conf</filename>. For reference on the config file syntax and options, "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"consult the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> manual page."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:135
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "<option>--version</option>"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:139
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Print version number and exit."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:147
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Signals"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:150
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SIGTERM/SIGINT"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:153
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Informs the SSSD to gracefully terminate all of its child processes and then "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"shut down the monitor."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:159
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SIGHUP"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:162
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Tells the SSSD to stop writing to its current debug file descriptors and to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"close and reopen them. This is meant to facilitate log rolling with programs "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"like logrotate."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:170
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SIGUSR1"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd.8.xml:173
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Tells the SSSD to simulate offline operation for the duration of the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>offline_timeout</quote> parameter. This is useful for testing. The "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"signal can be sent to either the sssd process or any sssd_be process "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"directly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd.8.xml:182
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SIGUSR2"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd.8.xml:185
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Tells the SSSD to go online immediately. This is useful for testing. The "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"signal can be sent to either the sssd process or any sssd_be process "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"directly."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sssd.8.xml:197
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"applications will not use the fast in memory cache."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_obfuscate"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "obfuscate a clear text password"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable></arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_obfuscate</command> converts a given password into human-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"unreadable format and places it into appropriate domain section of the SSSD "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"config file."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_obfuscate.8.xml:37
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The cleartext password is read from standard input or entered "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"interactively. The obfuscated password is put into "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>ldap_default_authtok</quote> parameter of a given SSSD domain and the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>ldap_default_authtok_type</quote> parameter is set to "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<quote>obfuscated_password</quote>. Refer to <citerefentry> "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"citerefentry> for more details on these parameters."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:49
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please note that obfuscating the password provides <emphasis>no real "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"security benefit</emphasis> as it is still possible for an attacker to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"reverse-engineer the password back. Using better authentication mechanisms "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"advised."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:63
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-s</option>,<option>--stdin</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:67
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The password to obfuscate will be read from standard input."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:70
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:78
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:79
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The SSSD domain to use the password in. The default name is <quote>default</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"quote>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:86
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:91
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Read the config file specified by the positional parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#: sss_obfuscate.8.xml:95
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: <filename>/etc/sssd/sssd.conf</filename>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:10 sss_override.8.xml:15
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "sss_override"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:16
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "create local overrides of user and group attributes"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>opties</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"replaceable> </arg> <arg choice='plain'><replaceable>GROEP</replaceable></"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:32
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_override</command> enables to create a client-side view and "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"allows to change selected values of specific user and groups. This change "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"takes effect only on local machine."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:37
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Overrides data are stored in the SSSD cache. If the cache is deleted, all "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"local overrides are lost. Please note that after the first override is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"created using any of the following <emphasis>user-add</emphasis>, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> or "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>group-import</emphasis> command. SSSD needs to be restarted to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"take effect. <emphasis>sss_override</emphasis> prints message when a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"restart is required."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_override.8.xml:50 sssctl.8.xml:42
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "AVAILABLE COMMANDS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:52
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Argument <emphasis>NAME</emphasis> is the name of original object in all "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"commands. It is not possible to override <emphasis>uid</emphasis> or "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>gid</emphasis> to 0."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:59
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optional> <optional><option>-g,--gid</option> GID</optional> "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<optional><option>-h,--home</option> HOME</optional> <optional><option>-s,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"shell</option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"CERTIFICATE</optional>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:72
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Override attributes of an user. Please be aware that calling this command "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"will replace any previous override for the (NAMEd) user."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:80
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-del</option> <emphasis>NAME</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:85
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Remove user overrides. However be aware that overridden attributes might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"returned from memory cache. Please see SSSD option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:94
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:99
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is set, only users from the domain are listed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:107
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>user-show</option> <emphasis>NAME</emphasis>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:112
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Show user overrides."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:118
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-import</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:123
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Import user overrides from <emphasis>FILE</emphasis>. Data format is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"similar to standard passwd file. The format is:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:128
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:131
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"where original_name is original name of the user whose attributes should be "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"overridden. The rest of fields correspond to new values. You can omit a "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"value simply by leaving corresponding field empty."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:140
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ckent:superman::::::"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:143
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:149
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-export</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:154
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Export all overridden attributes and store them in <emphasis>FILE</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis>. See <emphasis>user-import</emphasis> for data format."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:162
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optional>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:169
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Override attributes of a group. Please be aware that calling this command "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"will replace any previous override for the (NAMEd) group."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:177
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-del</option> <emphasis>NAME</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:182
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Remove group overrides. However be aware that overridden attributes might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"returned from memory cache. Please see SSSD option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:191
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:196
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"List all groups with set overrides. If <emphasis>DOMAIN</emphasis> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"parameter is set, only groups from the domain are listed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:204
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>group-show</option> <emphasis>NAME</emphasis>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:209
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Show group overrides."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:215
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-import</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:220
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Import group overrides from <emphasis>FILE</emphasis>. Data format is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"similar to standard group file. The format is:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:225
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "original_name:name:gid"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:228
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"where original_name is original name of the group whose attributes should be "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"overridden. The rest of fields correspond to new values. You can omit a "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"value simply by leaving corresponding field empty."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:237
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "admins:administrators:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:240
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Domain Users:Users:501"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:246
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-export</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:251
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Export all overridden attributes and store them in <emphasis>FILE</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis>. See <emphasis>group-import</emphasis> for data format."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_override.8.xml:261 sssctl.8.xml:51
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "OPTIONS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "COMMON OPTIONS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "OPTIES"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_override.8.xml:263 sssctl.8.xml:53
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Those options are available with all commands."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_override.8.xml:268 sssctl.8.xml:58
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>--debug</option> <replaceable>LEVEL</replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<option>-a</option>,<option>--append-group</option> <replaceable>GROEPEN</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:10 sss_useradd.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_useradd"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "create a new user"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_useradd</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_useradd</command> creates a new user account using the values "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"specified on the command line plus the default values from the system."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:43 sss_seed.8.xml:76
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:48
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Set the UID of the user to the value of <replaceable>UID</replaceable>. If "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"not given, it is chosen automatically."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:55 sss_usermod.8.xml:43 sss_seed.8.xml:100
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:60 sss_usermod.8.xml:48 sss_seed.8.xml:105
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Any text string describing the user. Often used as the field for the user's "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"full name."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:67 sss_usermod.8.xml:55 sss_seed.8.xml:112
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:72
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The home directory of the user account. The default is to append the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>LOGIN</replaceable> name to <filename>/home</filename> and use "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"that as the home directory. The base that is prepended before "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<replaceable>LOGIN</replaceable> is tunable with <quote>user_defaults/"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"baseDirectory</quote> setting in sssd.conf."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:82 sss_usermod.8.xml:66 sss_seed.8.xml:124
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:87
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The user's login shell. The default is currently <filename>/bin/bash</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"filename>. The default can be changed with <quote>user_defaults/"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"defaultShell</quote> setting in sssd.conf."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:96
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-G</option>,<option>--groups</option> <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:101
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "A list of existing groups this user is also a member of."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:107
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-m</option>,<option>--create-home</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:111
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Create the user's home directory if it does not exist. The files and "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directories contained in the skeleton directory (which can be defined with "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the -k option or in the config file) will be copied to the home directory."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:121
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-M</option>,<option>--no-create-home</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:125
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Do not create the user's home directory. Overrides configuration settings."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:132
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<option>-k</option>,<option>--skel</option> <replaceable>SKELDIR</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:137
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The skeleton directory, which contains files and directories to be copied in "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the user's home directory, when the home directory is created by "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_useradd</command>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_useradd.8.xml:143
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"Special files (block devices, character devices, named pipes and unix "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"sockets) will not be copied."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:147
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option is only valid if the <option>-m</option> (or <option>--create-"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"home</option>) option is specified, or creation of home directories is set "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"to TRUE in the configuration."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:156 sss_usermod.8.xml:124
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-Z</option>,<option>--selinux-user</option> "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>SELINUX_USER</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:161
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The SELinux user for the user's login. If not specified, the system default "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"will be used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sssd-krb5"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD Kerberos provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:23
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This manual page describes the configuration of the Kerberos 5 "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"authentication backend for <citerefentry> <refentrytitle>sssd</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. For a detailed "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"syntax reference, please refer to the <quote>FILE FORMAT</quote> section of "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"manvolnum> </citerefentry> manual page."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:36
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The Kerberos 5 authentication backend contains auth and chpass providers. It "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"must be paired with an identity provider in order to function properly (for "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"example, id_provider = ldap). Some information required by the Kerberos 5 "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"authentication backend must be provided by the identity provider, such as "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"the user's Kerberos Principal Name (UPN). The configuration of the identity "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"provider should have an entry to specify the UPN. Please refer to the man "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"page for the applicable identity provider for details on how to configure "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:47
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This backend also provides access control based on the .k5login file in the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"home directory of the user. See <citerefentry> <refentrytitle>.k5login</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"refentrytitle><manvolnum>5</manvolnum> </citerefentry> for more details. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Please note that an empty .k5login file will deny all access to this user. "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"To activate this feature, use 'access_provider = krb5' in your SSSD "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"configuration."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:55
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"In the case where the UPN is not available in the identity backend, "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sssd</command> will construct a UPN using the format "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#: sssd-krb5.5.xml:77
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Specifies the comma-separated list of IP addresses or hostnames of the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Kerberos servers to which SSSD should connect, in the order of preference. "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"For more information on failover and server redundancy, see the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>FAILOVER</quote> section. An optional port number (preceded by a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"colon) may be appended to the addresses or hostnames. If empty, service "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"discovery is enabled; for more information, refer to the <quote>SERVICE "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"DISCOVERY</quote> section."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:106
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The name of the Kerberos realm. This option is required and must be "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"specified."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:113
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "krb5_kpasswd, krb5_backup_kpasswd (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:116
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"If the change password service is not running on the KDC, alternative "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"servers can be defined here. An optional port number (preceded by a colon) "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"may be appended to the addresses or hostnames."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:122
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For more information on failover and server redundancy, see the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>FAILOVER</quote> section. NOTE: Even if there are no more kpasswd "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"servers to try, the backend is not switched to operate offline if "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"authentication against the KDC is still possible."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:129
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: Use the KDC"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:135
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_ccachedir (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:138
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Directory to store credential caches. All the substitution sequences of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"krb5_ccname_template can be used here, too, except %d and %P. The directory "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is created as private and owned by the user, with permissions set to 0700."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:145
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: /tmp"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:151
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_ccname_template (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:165 include/override_homedir.xml:11
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%u"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:166 include/override_homedir.xml:12
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "login name"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:169 include/override_homedir.xml:15
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%U"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:170
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "login UID"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:173
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "%p"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:174
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "principal name"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:178
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "%r"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:179
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "realm name"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:182
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "%h"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:183 sssd-ifp.5.xml:108
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "home directory"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:187 include/override_homedir.xml:19
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%d"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:188
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "value of krb5_ccachedir"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:193 include/override_homedir.xml:27
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "%P"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:194
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "the process ID of the SSSD client"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:199 include/override_homedir.xml:45
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%%"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:200 include/override_homedir.xml:46
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "a literal '%'"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:154
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Location of the user's credential cache. Three credential cache types are "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"currently supported: <quote>FILE</quote>, <quote>DIR</quote> and "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"<quote>KEYRING:persistent</quote>. The cache can be specified either as "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"<replaceable>TYPE:RESIDUAL</replaceable>, or as an absolute path, which "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"implies the <quote>FILE</quote> type. In the template, the following "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"sequences are substituted: <placeholder type=\"variablelist\" id=\"0\"/> If "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"the template ends with 'XXXXXX' mkstemp(3) is used to create a unique "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"filename in a safe way."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:208
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"When using KEYRING types, the only supported mechanism is <quote>KEYRING:"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"persistent:%U</quote>, which uses the Linux kernel keyring to store "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"credentials on a per-UID basis. This is also the recommended choice, as it "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"is the most secure and predictable method."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:216
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"The default value for the credential cache name is sourced from the profile "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"stored in the system wide krb5.conf configuration file in the [libdefaults] "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"section. The option name is default_ccache_name. See krb5.conf(5)'s "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"PARAMETER EXPANSION paragraph for additional information on the expansion "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"format defined by krb5.conf."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:225
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"NOTE: Please be aware that libkrb5 ccache expansion template from "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"manvolnum> </citerefentry> uses different expansion sequences than SSSD."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:234
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "Default: (from libkrb5)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:240
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_auth_timeout (integer)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:243
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Timeout in seconds after an online authentication request or change password "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"request is aborted. If possible, the authentication request is continued "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"offline."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:257
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Verify with the help of krb5_keytab that the TGT obtained has not been "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"spoofed. The keytab is checked for entries sequentially, and the first entry "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"with a matching realm is used for validation. If no entry matches the realm, "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"the last entry in the keytab is used. This process can be used to validate "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"environments using cross-realm trust by placing the appropriate keytab entry "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"as the last entry or the only entry in the keytab file."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:272
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_keytab (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:275
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The location of the keytab to use when validating credentials obtained from "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"KDCs."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:279
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: /etc/krb5.keytab"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:285
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_store_password_if_offline (boolean)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:288
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Store the password of the user if the provider is offline and use it to "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"request a TGT when the provider comes online again."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:293
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: this feature is only available on Linux. Passwords stored in this way "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"are kept in plaintext in the kernel keyring and are potentially accessible "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"by the root user (with difficulty)."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:306
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_renewable_lifetime (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:309
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Request a renewable ticket with a total lifetime, given as an integer "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"immediately followed by a time unit:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:314 sssd-krb5.5.xml:348 sssd-krb5.5.xml:385
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>s</emphasis> for seconds"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:317 sssd-krb5.5.xml:351 sssd-krb5.5.xml:388
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>m</emphasis> for minutes"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:320 sssd-krb5.5.xml:354 sssd-krb5.5.xml:391
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>h</emphasis> for hours"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:323 sssd-krb5.5.xml:357 sssd-krb5.5.xml:394
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>d</emphasis> for days."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:326 sssd-krb5.5.xml:397
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If there is no unit given, <emphasis>s</emphasis> is assumed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:330 sssd-krb5.5.xml:401
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: It is not possible to mix units. To set the renewable lifetime to one "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"and a half hours, use '90m' instead of '1h30m'."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:335
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set, i.e. the TGT is not renewable"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:341
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "krb5_lifetime (string)"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:344
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Request ticket with a lifetime, given as an integer immediately followed by "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"a time unit:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:360
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If there is no unit given <emphasis>s</emphasis> is assumed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:364
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: It is not possible to mix units. To set the lifetime to one and a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"half hours please use '90m' instead of '1h30m'."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:369
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Default: not set, i.e. the default ticket lifetime configured on the KDC."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:376
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "krb5_renew_interval (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:379
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The time in seconds between two checks if the TGT should be renewed. TGTs "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"are renewed if about half of their lifetime is exceeded, given as an integer "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"immediately followed by a time unit:"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:406
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If this option is not set or is 0 the automatic renewal is disabled."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:424
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<emphasis>never</emphasis> use FAST. This is equivalent to not setting this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"option at all."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:428
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"continue the authentication without it."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:438
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Default: not set, i.e. FAST is not used."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:441
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "NOTE: a keytab is required to use FAST."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:453
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "krb5_fast_principal (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:456
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgid "Specifies the server principal to use for FAST."
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallaghermsgstr ""
333b7970cc60c6277363c80564456a716c2d6634Stephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:465
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host and user principal should be canonicalized. This "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"feature is available with MIT Kerberos 1.7 and later versions."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:514
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: false (AD provider: true)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:520
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "krb5_map_user (string)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:523
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The list of mappings is given as a comma-separated list of pairs "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>username:primary</quote> where <quote>username</quote> is a UNIX user "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"name and <quote>primary</quote> is a user part of a kerberos principal. This "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"mapping is used when user is authenticating using <quote>auth_provider = "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5</quote>."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:535
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_realm = REALM\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_map_user = joe:juser,dick:richard\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:540
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>joe</quote> and <quote>dick</quote> are UNIX user names and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>juser</quote> and <quote>richard</quote> are primaries of kerberos "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"principals. For user <quote>joe</quote> resp. <quote>dick</quote> SSSD will "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"try to kinit as <quote>juser@REALM</quote> resp. <quote>richard@REALM</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"quote>."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sssd-krb5.5.xml:65
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"If the auth-module krb5 is used in an SSSD domain, the following options "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"must be used. See the <citerefentry> <refentrytitle>sssd.conf</"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page, section "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>DOMAIN SECTIONS</quote>, for details on the configuration of an SSSD "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain. <placeholder type=\"variablelist\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:566
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The following example assumes that SSSD is correctly configured and FOO is "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"one of the domains in the <replaceable>[sssd]</replaceable> section. This "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"example shows only configuration of Kerberos authentication; it does not "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"include any identity provider."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:574
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#, no-wrap
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/FOO]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = krb5\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_server = 192.168.1.1\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_realm = EXAMPLE.COM\n"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupadd.8.xml:10 sss_groupadd.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_groupadd"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupadd.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "create a new group"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupadd.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupadd</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupadd.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupadd</command> creates a new group. These groups are "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"compatible with POSIX groups, with the additional feature that they can "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"contain other groups as members."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_groupadd.8.xml:43 sss_seed.8.xml:88
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupadd.8.xml:48
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Set the GID of the group to the value of <replaceable>GID</replaceable>. If "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"not given, it is chosen automatically."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:10 sss_userdel.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_userdel"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "delete a user account"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_userdel</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_userdel</command> deletes a user identified by login name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>LOGIN</replaceable> from the system."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:44
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-r</option>,<option>--remove</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:48
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Files in the user's home directory will be removed along with the home "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directory itself and the user's mail spool. Overrides the configuration."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:56
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-R</option>,<option>--no-remove</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:60
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Files in the user's home directory will NOT be removed along with the home "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directory itself and the user's mail spool. Overrides the configuration."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:68
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-f</option>,<option>--force</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:72
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"This option forces <command>sss_userdel</command> to remove the user's home "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"directory and mail spool, even if they are not owned by the specified user."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:80
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-k</option>,<option>--kick</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_userdel.8.xml:84
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Before actually deleting the user, terminate all his processes."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:10 sss_groupdel.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_groupdel"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "delete a group"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupdel</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupdel.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupdel</command> deletes a group identified by its name "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>GROUP</replaceable> from the system."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:10 sss_groupshow.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_groupshow"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "print properties of a group"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_groupshow</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_groupshow</command> displays information about a group "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"identified by its name <replaceable>GROUP</replaceable>. The information "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"includes the group ID number, members of the group and the parent group."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:43
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-R</option>,<option>--recursive</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_groupshow.8.xml:47
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Also print indirect group members in a tree-like hierarchy. Note that this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"also affects printing parent groups - without <option>R</option>, only the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"direct parent will be printed."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:10 sss_usermod.8.xml:15
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "sss_usermod"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:16
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "modify a user account"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:21
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<command>sss_usermod</command> <arg choice='opt'> <replaceable>options</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"arg>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:32
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<command>sss_usermod</command> modifies the account specified by "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"<replaceable>LOGIN</replaceable> to reflect the changes that are specified "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"on the command line."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:60
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The home directory of the user account."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:71
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The user's login shell."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:82
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Append this user to groups specified by the <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter is "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"a comma separated list of group names."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:96
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"Remove this user from groups specified by the <replaceable>GROUPS</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"replaceable> parameter."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:103
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-l</option>,<option>--lock</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:107
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Lock the user account. The user won't be able to log in."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:114
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<option>-u</option>,<option>--unlock</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:118
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Unlock the user account."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: sss_usermod.8.xml:129
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The SELinux user for the user's login."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:135
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--addattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:140
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Add an attribute/value pair. The format is attrname=value."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:147
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--setattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:152
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Set an attribute to a name/value pair. The format is attrname=value. For "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"multi-valued attributes, the command replaces the values already present"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:160
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--delattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:165
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Delete an attribute/value pair. The format is attrname=value."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:10 sss_cache.8.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_cache"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "perform cache cleanup"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_cache</command> <arg choice='opt'> <replaceable>options</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable> </arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:31
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_cache</command> invalidates records in SSSD cache. Invalidated "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"records are forced to be reloaded from server as soon as related SSSD "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"backend is online."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:42
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "<option>-E</option>,<option>--everything</option>"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:46
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Invalidate all cached entries."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:52
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:57
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific user."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:63
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-U</option>,<option>--users</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:67
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all user records. This option overrides invalidation of specific "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"user if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:74
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:79
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific group."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:85
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-G</option>,<option>--groups</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:89
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all group records. This option overrides invalidation of specific "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"group if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:96
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:101
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific netgroup."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:107
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-N</option>,<option>--netgroups</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:111
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all netgroup records. This option overrides invalidation of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"specific netgroup if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:118
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-s</option>,<option>--service</option> <replaceable>service</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:123
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Invalidate specific service."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:129
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>-S</option>,<option>--services</option>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:133
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Invalidate all service records. This option overrides invalidation of "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"specific service if it was also set."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:140
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:145
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Invalidate specific autofs maps."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:151
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>-A</option>,<option>--autofs-maps</option>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:155
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Invalidate all autofs maps. This option overrides invalidation of specific "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"map if it was also set."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:162
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_cache.8.xml:167
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Invalidate SSH public keys of a specific host."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_cache.8.xml:173
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "<option>-H</option>,<option>--ssh-hosts</option>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_cache.8.xml:177
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Invalidate SSH public keys of all hosts. This option overrides invalidation "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"of SSH public keys of specific host if it was also set."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_cache.8.xml:185
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-r</option>,<option>--remove-group</option> <replaceable>GROEPEN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_cache.8.xml:190
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Invalidate particular sudo rule."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_cache.8.xml:196
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>-R</option>,<option>--sudo-rules</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-a</option>,<option>--append-group</option> <replaceable>GROEPEN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_cache.8.xml:200
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Invalidate all cached sudo rules. This option overrides invalidation of "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"specific sudo rule if it was also set."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_cache.8.xml:208
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-d</option>,<option>--domain</option> <replaceable>domain</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_cache.8.xml:213
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Restrict invalidation process only to a particular domain."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_debuglevel"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "change debug level while SSSD is running"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>options</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:32
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_debuglevel</command> changes debug level of SSSD monitor and "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"providers to <replaceable>NEW_DEBUG_LEVEL</replaceable> while SSSD is "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"running."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:59
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<replaceable>NEW_DEBUG_LEVEL</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:10 sss_seed.8.xml:15
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sss_seed"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "seed the SSSD cache with a user"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:21
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<command>sss_seed</command> <arg choice='opt'> <replaceable>options</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMAIN</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable></arg> <arg choice='plain'>-n <replaceable>USER</replaceable></"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"arg>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:33
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<command>sss_seed</command> seeds the SSSD cache with a user entry and "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"temporary password. If a user entry is already present in the SSSD cache "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"then the entry is updated with the temporary password."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:46
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:51
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Provide the name of the domain in which the user is a member of. The domain "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"is also used to retrieve user information. The domain must be configured in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"sssd.conf. The <replaceable>DOMAIN</replaceable> option must be provided. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Information retrieved from the domain overrides what is provided in the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"options."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:63
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-n</option>,<option>--username</option> <replaceable>USER</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:68
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The username of the entry to be created or modified in the cache. The "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<replaceable>USER</replaceable> option must be provided."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:81
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the UID of the user to <replaceable>UID</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:93
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the GID of the user to <replaceable>GID</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:117
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Set the home directory of the user to <replaceable>HOME_DIR</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:129
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the login shell of the user to <replaceable>SHELL</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:140
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Interactive mode for entering user information. This option will only prompt "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"for information not provided in the options or retrieved from the domain."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:148
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:153
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Specify file to read user's password from. (if not specified password is "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"prompted for)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sss_seed.8.xml:165
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"The length of the password (or the size of file specified with -p or --"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"password-file option) must be less than or equal to PASS_MAX bytes (64 bytes "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"on systems with no globally-defined PASS_MAX value)."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sssd-ifp"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD InfoPipe responder"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:23
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This manual page describes the configuration of the InfoPipe responder for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:36
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The InfoPipe responder provides a public D-Bus interface accessible over the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"system bus. The interface allows the user to query information about remote "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"users and groups over the system bus."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:46
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "These options can be used to configure the InfoPipe responder."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:53
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"allowed to access the InfoPipe responder. User names are resolved to UIDs at "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"startup."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:59
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Default: 0 (only the root user is allowed to access the InfoPipe responder)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:63
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that although the UID 0 is used as the default it will be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"overwritten with this option. If you still want to allow the root user to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"access the InfoPipe responder, which would be the typical case, you have to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"add 0 to the list of allowed UIDs as well."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:77
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Specifies the comma-separated list of white or blacklisted attributes."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:91
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "name"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:92
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user's login name"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:95
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "uidNumber"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:96
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user ID"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:99
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "gidNumber"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:100
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "primary group ID"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:103
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "gecos"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:104
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user information, typically full name"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:107
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "homeDirectory"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:111
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "loginShell"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:112
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user shell"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:81
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"By default, the InfoPipe responder only allows the default set of POSIX "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"attributes to be requested. This set is the same as returned by "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry> and includes: <placeholder type=\"variablelist\" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:125
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#, no-wrap
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"user_attributes = +telephoneNumber, -loginShell\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:117
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"It is possible to add another attribute to this set by using <quote>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"+attr_name</quote> or explicitly remove an attribute using <quote>-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"attr_name</quote>. For example, to allow <quote>telephoneNumber</quote> but "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"deny <quote>loginShell</quote>, you would use the following configuration: "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:129
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: not set. Only the default set of POSIX attributes is allowed."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ifp.5.xml:139
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies an upper limit on the number of entries that are downloaded during "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"a wildcard lookup that overrides caller-supplied limit."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ifp.5.xml:144
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: 0 (let the caller set an upper limit)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refentryinfo>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:8
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<productname>sss rpc.idmapd plugin</productname> <author> <firstname>Noam</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"firstname> <surname>Meltzer</surname> <affiliation> <orgname>Primary Data "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Inc.</orgname> </affiliation> <contrib>Developer (2013-2014)</contrib> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"author> <author> <firstname>Noam</firstname> <surname>Meltzer</surname> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<contrib>Developer (2014-)</contrib> <email>tsnoam@gmail.com</email> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"author>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sss_rpcidmapd"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:33
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sss plugin configuration directives for rpc.idmapd"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:37
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "CONFIGURATION FILE"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:39
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"rpc.idmapd configuration file is usually found at <emphasis>/etc/idmapd."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"conf</emphasis>. See <citerefentry> <refentrytitle>idmapd.conf</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more information."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:49
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SSS CONFIGURATION EXTENSION"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:51
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Enable SSS plugin"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:53
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attribute to contain <emphasis>sss</emphasis>."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:59
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "[sss] config section"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:61
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"In order to change the default of one of the configuration attributes of the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<emphasis>sss</emphasis> plugin listed below you will need to create a "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"config section for it, named <quote>[sss]</quote>."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:67
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Configuration attributes"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:69
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "memcache (bool)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:72
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Indicates whether or not to use memcache optimisation technique."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:85
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SSSD INTEGRATION"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:87
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"in sssd."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:91
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The attribute <quote>use_fully_qualified_names</quote> must be enabled on "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"all domains (NFSv4 clients expect a fully qualified name to be sent on the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"wire)."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:103
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[General]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Verbosity = 2\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"# domain must be synced between NFSv4 server and clients\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"# Solaris/Illumos/AIX use \"localdomain\" as default!\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Domain = default\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[Mapping]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Nobody-User = nfsnobody\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Nobody-Group = nfsnobody\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[Translation]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Method = sss\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:100
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The following example shows a minimal idmapd.conf which makes use of the sss "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"plugin. <placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:120 include/seealso.xml:2
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SEE ALSO"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "ZIE OOK"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:122
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_ssh_authorizedkeys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhostsproxy.1.xml:11
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "1"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "get OpenSSH authorized keys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>options</replaceable> </arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='plain'><replaceable>USER</replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:32
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_authorizedkeys</command> acquires SSH public keys for user "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>USER</replaceable> and outputs them in OpenSSH authorized_keys "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"format (see the <quote>AUTHORIZED_KEYS FILE FORMAT</quote> section of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> for more information)."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:41
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> can be configured to use <command>sss_ssh_authorizedkeys</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"command> for public key user authentication if it is compiled with support "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for <quote>AuthorizedKeysCommand</quote> option. Please refer to the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<citerefentry> <refentrytitle>sshd_config</refentrytitle> <manvolnum>5</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"manvolnum></citerefentry> man page for more details about this option."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:59
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" AuthorizedKeysCommandUser nobody\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:52
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"If <quote>AuthorizedKeysCommand</quote> is supported, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"citerefentry> can be configured to use it by putting the following "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"directives in <citerefentry> <refentrytitle>sshd_config</refentrytitle> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<manvolnum>5</manvolnum></citerefentry>: <placeholder type=\"programlisting"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:75
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Search for user public keys in SSSD domain <replaceable>DOMAIN</replaceable>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:84 sss_ssh_knownhostsproxy.1.xml:92
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "EXIT STATUS"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:86 sss_ssh_knownhostsproxy.1.xml:94
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"In case of success, an exit value of 0 is returned. Otherwise, 1 is returned."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:10 sss_ssh_knownhostsproxy.1.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_ssh_knownhostsproxy"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "get OpenSSH host keys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_knownhostsproxy</command> <arg choice='opt'> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>options</replaceable> </arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='plain'><replaceable>HOST</replaceable></arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='opt'><replaceable>PROXY_COMMAND</replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:33
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_knownhostsproxy</command> acquires SSH host public keys for "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"host <replaceable>HOST</replaceable>, stores them in a custom OpenSSH "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"known_hosts file (see the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"manvolnum></citerefentry> for more information) <filename>/var/lib/sss/"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"pubconf/known_hosts</filename> and estabilishes connection to the host."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:43
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"If <replaceable>PROXY_COMMAND</replaceable> is specified, it is used to "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"create the connection to the host instead of opening a socket."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:55
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#, no-wrap
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:48
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> can be configured to use <command>sss_ssh_knownhostsproxy</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"command> for host key authentication by using the following directives for "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> configuration: <placeholder type=\"programlisting\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:66
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:71
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Use port <replaceable>PORT</replaceable> to connect to the host. By "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"default, port 22 is used."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:83
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Search for host public keys in SSSD domain <replaceable>DOMAIN</replaceable>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:10 idmap_sss.8.xml:15
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "idmap_sss"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:16
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "SSSSD's idmap_sss Backend for Winbind"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:22
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and SIDs. "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"No database is required in this case as the mapping is done by SSSD."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:29
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, fuzzy
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#| msgid "OPTIONS"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "IDMAP OPTIONS"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr "OPTIES"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:33
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "range = low - high"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:35
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"Defines the available matching uid and gid range for which the backend is "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"authoritative."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:43
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "EXAMPLES"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:45
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"This example shows how to configure idmap_sss as the default mapping module."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><programlisting>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:50
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, no-wrap
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"[global]\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"security = domain\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"workgroup = MAIN\n"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"idmap config * : backend = sss\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"idmap config * : range = 200000-2147483647\n"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek" "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:10 sssctl.8.xml:15
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "sssctl"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:16
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "SSSD control and status utility"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:21
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#, fuzzy
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| msgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<command>sssctl</command> <arg choice='plain'><replaceable>COMMAND</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>opties</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"replaceable> </arg> <arg choice='plain'><replaceable>GROEP</replaceable></"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:32
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<command>sssctl</command> provides simple and unified way to obtain "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"information about SSSD status such as active server or list of auto-"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"discovered servers and domains or information about cached objects. It also "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"provides tools to manage SSSD data files during troubleshooting such as a "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"safe way to remove cache files or fetching all SSSD log files and more."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:44
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"To list all available commands run <command>sssctl</command> without any "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"parameter. To print help for selected command run <command>sssctl COMMAND --"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"help</command>."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:2
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "SERVICE DISCOVERY"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:4
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The service discovery feature allows back ends to automatically find the "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"appropriate servers to connect to using a special DNS query. This feature is "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"not supported for backup servers."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Configuration"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:11
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If no servers are specified, the back end automatically uses service "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"discovery to try to find a server. Optionally, the user may choose to use "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"both fixed server addresses and service discovery by inserting a special "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"keyword, <quote>_srv_</quote>, in the list of servers. The order of "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"preference is maintained. This feature is useful if, for example, the user "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"prefers to use service discovery whenever possible, and fall back to a "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"specific server when no servers can be discovered using DNS."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:23
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The domain name"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:25
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Please refer to the <quote>dns_discovery_domain</quote> parameter in the "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"manvolnum> </citerefentry> manual page for more details."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:35
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The protocol"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:37
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The queries usually specify _tcp as the protocol. Exceptions are documented "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"in respective option description."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:42
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "See Also"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/service_discovery.xml:44
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"For more information on the service discovery mechanism, refer to RFC 2782."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: outside any tag (error?)
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/upstream.xml:1
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "<placeholder type=\"refentryinfo\" id=\"0\"/>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/failover.xml:2
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "FAILOVER"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/failover.xml:4
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The failover feature allows back ends to automatically switch to a different "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"server if the current server fails."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/failover.xml:8
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Failover Syntax"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/failover.xml:10
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The list of servers is given as a comma-separated list; any number of spaces "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"is allowed around the comma. The servers are listed in order of preference. "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"The list can contain any number of servers."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"For each failover-enabled config option, two variants exist: "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>primary</emphasis> and <emphasis>backup</emphasis>. The idea is "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"that servers in the primary list are preferred and backup servers are only "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"searched if no primary servers can be reached. If a backup server is "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"selected, a timeout of 31 seconds is set. After this timeout SSSD will "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"periodically try to reconnect to one of the primary servers. If it succeeds, "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"it will replace the current active (backup) server."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:27
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "The Failover Mechanism"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:29
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"The failover mechanism distinguishes between a machine and a service. The "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"back end first tries to resolve the hostname of a given machine; if this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"resolution attempt fails, the machine is considered offline. No further "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"attempts are made to connect to this machine for any other service. If the "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"resolution attempt succeeds, the back end tries to connect to a service on "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"this machine. If the service connection attempt fails, then only this "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"particular service is considered offline and the back end automatically "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"switches over to the next service. The machine is still considered online "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"and might still be tried for another service."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:42
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"Further connection attempts are made to machines or services marked as "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"offline after a specified period of time; this is currently hard coded to 30 "
1008001f34abb42df75f840db17f14a83f0c21d4Stephen Gallagher"seconds."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:47
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"If there are no more machines to try, the back end as a whole switches to "
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher"offline mode, and then attempts to reconnect every 30 seconds."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:2
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ID MAPPING"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:4
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The ID-mapping feature allows SSSD to act as a client of Active Directory "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"without requiring administrators to extend user attributes to support POSIX "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"attributes for user and group identifiers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:9
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: When ID-mapping is enabled, the uidNumber and gidNumber attributes are "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ignored. This is to avoid the possibility of conflicts between automatically-"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"assigned and manually-assigned values. If you need to use manually-assigned "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"values, ALL values must be manually-assigned."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that changing the ID mapping related configuration options will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"cause user and group IDs to change. At the moment, SSSD does not support "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"changing IDs, so the SSSD database must be removed. Because cached passwords "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"are also stored in the database, removing the database should only be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"performed while the authentication servers are reachable, otherwise users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"might get locked out. In order to cache the password, an authentication must "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"be performed. It is not sufficient to use <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> to remove the database, rather the process consists of:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:33
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Making sure the remote servers are reachable"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:38
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Stopping the SSSD service"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:43
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Removing the database"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:48
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Starting the SSSD service"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:52
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Moreover, as the change of IDs might necessitate the adjustment of other "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"system properties such as file and directory ownership, it's advisable to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"plan ahead and test the ID mapping configuration thoroughly."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:59
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Mapping Algorithm"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:61
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory provides an objectSID for every user and group object in "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the directory. This objectSID can be broken up into components that "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"represent the Active Directory domain identity and the relative identifier "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"(RID) of the user or group object."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:67
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The SSSD ID-mapping algorithm takes a range of available UIDs and divides it "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"into equally-sized component sections - called \"slices\"-. Each slice "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"represents the space available to an Active Directory domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:73
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When a user or group entry for a particular domain is encountered for the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"first time, the SSSD allocates one of the available slices for that domain. "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"In order to make this slice-assignment repeatable on different client "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"machines, we select the slice based on the following algorithm:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:80
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The SID string is passed through the murmurhash3 algorithm to convert it to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"a 32-bit hashed value. We then take the modulus of this value with the total "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"number of available slices to pick the slice."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:86
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: It is possible to encounter collisions in the hash and subsequent "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"modulus. In these situations, we will select the next available slice, but "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"it may not be possible to reproduce the same exact set of slices on other "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"machines (since the order that they are encountered will determine their "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"slice). In this situation, it is recommended to either switch to using "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"explicit POSIX attributes in Active Directory (disabling ID-mapping) or "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"configure a default domain to guarantee that at least one is always "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"consistent. See <quote>Configuration</quote> for details."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:101
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:106
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#, no-wrap
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_id_mapping = True\n"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_schema = ad\n"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:111
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The default configuration results in configuring 10,000 slices, each capable "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"of holding up to 200,000 IDs, starting from 10,001 and going up to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"2,000,100,000. This should be sufficient for most deployments."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:117
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Advanced Configuration"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:120
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_min (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:123
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the lower bound of the range of POSIX IDs to use for mapping "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory user and group SIDs."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:127
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"NOTE: This option is different from <quote>min_id</quote> in that "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<quote>min_id</quote> acts to filter the output of requests to this domain, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"whereas this option controls the range of ID assignment. This is a subtle "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"distinction, but the good general advice would be to have <quote>min_id</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> be less-than or equal to <quote>ldap_idmap_range_min</quote>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:137 include/ldap_id_mapping.xml:191
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: 200000"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:142
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_max (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:145
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the upper bound of the range of POSIX IDs to use for mapping "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory user and group SIDs."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:149
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"NOTE: This option is different from <quote>max_id</quote> in that "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<quote>max_id</quote> acts to filter the output of requests to this domain, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"whereas this option controls the range of ID assignment. This is a subtle "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"distinction, but the good general advice would be to have <quote>max_id</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> be greater-than or equal to <quote>ldap_idmap_range_max</quote>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:159
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: 2000200000"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:164
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_size (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:167
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the number of IDs available for each slice. If the range size "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"does not divide evenly into the min and max values, it will create as many "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"complete slices as it can."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:173
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: The value of this option must be at least as large as the highest user "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"RID planned for use on the Active Directory server. User lookups and login "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"will fail for any user whose RID is greater than this value."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:179
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"For example, if your most recently-added Active Directory user has "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"objectSid=S-1-5-21-2153326666-2176343378-3404031434-1107, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"equal to maximal SID minus minimal SID plus one (e.g. 1108 = 1107 - 0 + 1)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:186
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"It is important to plan ahead for future expansion, as changing this value "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"will result in changing all of the ID mappings on the system, leading to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"users with different local IDs than they previously had."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:196
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_default_domain_sid (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:199
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specify the domain SID of the default domain. This will guarantee that this "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"domain will always be assigned to slice zero in the ID map, bypassing the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"murmurhash algorithm described above."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:210
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_default_domain (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:213
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Specify the name of the default domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:221
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_autorid_compat (boolean)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:224
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Changes the behavior of the ID-mapping algorithm to behave more similarly to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"winbind's <quote>idmap_autorid</quote> algorithm."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:229
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When this option is configured, domains will be allocated starting with "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"slice zero and increasing monatomically with each additional domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:234
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: This algorithm is non-deterministic (it depends on the order that "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"users and groups are requested). If this mode is required for compatibility "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"with machines running winbind, it is recommended to also use the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"least one domain is consistently allocated to slice zero."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:249
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_idmap_helper_table_size (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:252
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Maximal number of secondary slices that is tried when performing mapping "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from UNIX id to SID."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:256
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Additional secondary slices might be generated when SID is being "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"mapped to UNIX id and RID part of SID is out of range for secondary slices "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"generated so far. If value of ldap_idmap_helper_table_size is equal to 0 "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"then no additional secondary slices are generated."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:273
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Well-Known SIDs"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:275
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD supports to look up the names of Well-Known SIDs, i.e. SIDs with a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"special hardcoded meaning. Since the generic users and groups related to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"those Well-Known SIDs have no equivalent in a Linux/UNIX environment no "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"POSIX IDs are available for those objects."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:281
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The SID name space is organized in authorities which can be seen as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"different domains. The authorities for the Well-Known SIDs are"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:284
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Null Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:285
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "World Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:286
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Local Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:287
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Creator Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:288
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "NT Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:289
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Built-in"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:291
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The capitalized version of these names are used as domain names when "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"returning the fully qualified name of a Well-Known SID."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:295
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Since some utilities allow to modify SID based access control information "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"with the help of a name instead of using the SID directly SSSD supports to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"look up the SID by the name as well. To avoid collisions only the fully "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"qualified names can be used to look up Well-Known SIDs. As a result the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain names <quote>NULL AUTHORITY</quote>, <quote>WORLD AUTHORITY</quote>, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote> LOCAL AUTHORITY</quote>, <quote>CREATOR AUTHORITY</quote>, <quote>NT "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"AUTHORITY</quote> and <quote>BUILTIN</quote> should not be used as domain "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"names in <filename>sssd.conf</filename>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <varlistentry><term>
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#: include/param_help.xml:3
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "<option>-?</option>,<option>--help</option>"
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallagher#. type: Content of: <varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/param_help.xml:7 include/param_help_py.xml:7
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgid "Display help message and exit."
6b0f9cd2ee601121cb7fe1d9ad8ebce782aa8f39Stephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/param_help_py.xml:3
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "<option>-h</option>,<option>--help</option>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: include/debug_levels.xml:3
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD supports two representations for specifying the debug level. The "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"simplest is to specify a decimal value from 0-9, which represents enabling "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that level and all lower-level debug messages. The more comprehensive option "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is to specify a hexadecimal bitmask to enable or disable specific levels "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"(such as if you wish to suppress a level)."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/debug_levels.xml:10
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Please note that each SSSD service logs into its own log file. Also please "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"note that enabling <quote>debug_level</quote> in the <quote>[sssd]</quote> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"section only enables debugging just for the sssd process itself, not for the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"responder or provider processes. The <quote>debug_level</quote> parameter "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"should be added to all sections that you wish to produce debug logs from."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:18
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"In addition to changing the log level in the config file using the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>debug_level</quote> parameter, which is persistent, but requires SSSD "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"restart, it is also possible to change the debug level on the fly using the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> <manvolnum>8</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"manvolnum> </citerefentry> tool."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:29
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Currently supported debug levels:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:32
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Fatal failures. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Anything that would prevent SSSD from starting up or causes it to cease "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"running."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:38
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Critical failures. An "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"error that doesn't kill the SSSD, but one that indicates that at least one "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"major feature is not going to work properly."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:45
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"error announcing that a particular request or operation has failed."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:50
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Minor failures. These "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"are the errors that would percolate down to cause the operation failure of 2."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:55
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:59
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:63
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"operation functions."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:67
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"internal control functions."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:72
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of function-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"internal variables that may be interesting."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:77
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"tracing information."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:81
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"To log required bitmask debug levels, simply add their numbers together as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"shown in following examples:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:85
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>Example</emphasis>: To log fatal failures, critical failures, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"serious failures and function data use 0x0270."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:89
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>Example</emphasis>: To log fatal failures, configuration settings, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"function data, trace messages for internal control functions use 0x1310."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:94
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"in 1.7.0."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:98
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>Default</emphasis>: 0"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: outside any tag (error?)
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: include/experimental.xml:1
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis> This is an experimental feature, please use http://fedorahosted."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"org/sssd to report any issues. </emphasis>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:2
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "THE LOCAL DOMAIN"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:4
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"In order to function correctly, a domain with <quote>id_provider=local</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> must be created and the SSSD must be running."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:9
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The administrator might want to use the SSSD local users instead of "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"traditional UNIX users in cases where the group nesting (see <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry>) is needed. The local users are also useful for testing and "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"development of the SSSD without having to deploy a full remote server. The "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<command>sss_user*</command> and <command>sss_group*</command> tools use a "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"local LDB storage to store users and groups."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: include/seealso.xml:4
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd-ipa</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, <phrase condition=\"with_sudo\"> <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, </phrase> <citerefentry> <refentrytitle>sss_cache</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_groupadd</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_groupdel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_groupshow</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_groupmod</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_useradd</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_userdel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_usermod</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_obfuscate</refentrytitle><manvolnum>8</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_seed</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle><manvolnum>8</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"manvolnum> </citerefentry>, <phrase condition=\"with_ssh\"> <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>8</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"manvolnum> </citerefentry>, <citerefentry> "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<refentrytitle>sss_ssh_knownhostsproxy</refentrytitle> <manvolnum>8</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry>, </phrase> <phrase condition=\"with_ifp\"> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"manvolnum> </citerefentry>, </phrase> <citerefentry> <refentrytitle>pam_sss</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>. <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:3
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"An optional base DN, search scope and LDAP filter to restrict LDAP searches "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"for this attribute type."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para><programlisting>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:9
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#, no-wrap
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:7
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:13
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The scope can be one of \"base\", \"onelevel\" or \"subtree\". The scope "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"functions as specified in section 4.5.1.2 of http://tools.ietf.org/html/"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"rfc4511"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_search_bases.xml:23
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"For examples of this syntax, please refer to the <quote>ldap_search_base</"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"quote> examples section."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_search_bases.xml:31
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Please note that specifying scope or filter is not supported for searches "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"against an Active Directory Server that might yield a large number of "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"results and trigger the Range Retrieval extension in the response."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/autofs_restart.xml:2
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Please note that the automounter only reads the master map on startup, so if "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"any autofs-related changes are made to the sssd.conf, you typically also "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"need to restart the automounter daemon after restarting the SSSD."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:2
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "override_homedir (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:16
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "UID number"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:20
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "domain name"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:23
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%f"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:24
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "fully qualified user name (user@domain)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:28
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "UPN - User Principal Name (name@REALM)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:31
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%o"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:33
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "The original home directory retrieved from the identity provider."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:38
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "%H"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:40
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "The value of configure option <emphasis>homedir_substring</emphasis>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:5
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Override the user's home directory. You can either provide an absolute value "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"or a template. In the template, the following sequences are substituted: "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:52
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "This option can also be set per-domain."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><programlisting>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:57
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#, no-wrap
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"override_homedir = /home/%u\n"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek" "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:61
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: Not set (SSSD will use the value retrieved from LDAP)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:2
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "homedir_substring (string)"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:5
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The value of this option will be used in the expansion of the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<emphasis>override_homedir</emphasis> option if the template contains the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"format string <emphasis>%H</emphasis>. An LDAP directory entry can directly "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"contain this template so that this option can be used to expand the home "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"directory path for each client machine (or operating system). It can be set "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"per-domain or globally in the [nss] section. A value specified in a domain "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"section will override one set in the [nss] section."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:15
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Default: /home"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""