pt.po revision 0142e7e2558a887992b1c5d4dc3051178e377687
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# SOME DESCRIPTIVE TITLE
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# Copyright (C) YEAR Red Hat
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# This file is distributed under the same license as the sssd-docs package.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# Translators:
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek# Miguel Sousa <migueljorgesousa@sapo.pt>, 2011
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Project-Id-Version: sssd-docs 1.12.90\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Report-Msgid-Bugs-To: sssd-devel@redhat.com\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"POT-Creation-Date: 2016-10-19 20:57+0200\n"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"PO-Revision-Date: 2014-12-15 12:05-0500\n"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"Last-Translator: Copied by Zanata <copied-by-zanata@zanata.org>\n"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Language-Team: Portuguese (http://www.transifex.com/projects/p/sssd/language/"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"pt/)\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Language: pt\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"MIME-Version: 1.0\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Content-Type: text/plain; charset=UTF-8\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Content-Transfer-Encoding: 8bit\n"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"Plural-Forms: nplurals=2; plural=(n != 1);\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"X-Generator: Zanata 3.9.5\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:5 sssd.conf.5.xml:5 sssd-ldap.5.xml:5 pam_sss.8.xml:5
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:5 sssd-simple.5.xml:5 sssd-ipa.5.xml:5
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ad.5.xml:5 sssd-sudo.5.xml:5 sssd.8.xml:5 sss_obfuscate.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:5 sss_useradd.8.xml:5 sssd-krb5.5.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupadd.8.xml:5 sss_userdel.8.xml:5 sss_groupdel.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupshow.8.xml:5 sss_usermod.8.xml:5 sss_cache.8.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_debuglevel.8.xml:5 sss_seed.8.xml:5 sssd-ifp.5.xml:5
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_rpcidmapd.5.xml:5 sss_ssh_authorizedkeys.1.xml:5
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:5 idmap_sss.8.xml:5 sssctl.8.xml:5
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:5
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SSSD Manual pages"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Páginas de Manual de SSSD"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:10 sss_groupmod.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_groupmod"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sss_groupmod"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:11 pam_sss.8.xml:14 sssd_krb5_locator_plugin.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd.8.xml:11 sss_obfuscate.8.xml:11 sss_override.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_useradd.8.xml:11 sss_groupadd.8.xml:11 sss_userdel.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupdel.8.xml:11 sss_groupshow.8.xml:11 sss_usermod.8.xml:11
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_cache.8.xml:11 sss_debuglevel.8.xml:11 sss_seed.8.xml:11
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: idmap_sss.8.xml:11 sssctl.8.xml:11
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "8"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "8"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "modify a group"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "modificar um grupo"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_groupmod</command> <arg choice='opt'> <replaceable>Opções</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable></arg> <arg choice='plain'> <replaceable>grupo</replaceable></"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_groupmod.8.xml:30 sssd-ldap.5.xml:21 pam_sss.8.xml:56
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:20 sssd-simple.5.xml:22 sssd-ipa.5.xml:21
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-ad.5.xml:21 sssd-sudo.5.xml:21 sssd.8.xml:29 sss_obfuscate.8.xml:30
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:30 sss_useradd.8.xml:30 sssd-krb5.5.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupadd.8.xml:30 sss_userdel.8.xml:30 sss_groupdel.8.xml:30
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_groupshow.8.xml:30 sss_usermod.8.xml:30 sss_cache.8.xml:29
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_debuglevel.8.xml:30 sss_seed.8.xml:31 sssd-ifp.5.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:30 sss_ssh_knownhostsproxy.1.xml:31
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: idmap_sss.8.xml:20 sssctl.8.xml:30 sssd-secrets.5.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "DESCRIPTION"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "DESCRIÇÃO"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupmod</command> modifies the group to reflect the changes "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"that are specified on the command line."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_groupmod</command> modifica o grupo para refletir as alterações "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"que são especificadas na linha de comando."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_groupmod.8.xml:39 pam_sss.8.xml:63 sssd.8.xml:42 sss_obfuscate.8.xml:58
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:39 sss_groupadd.8.xml:39 sss_userdel.8.xml:39
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupdel.8.xml:39 sss_groupshow.8.xml:39 sss_usermod.8.xml:39
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:39 sss_debuglevel.8.xml:38 sss_seed.8.xml:42
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:66 sss_ssh_knownhostsproxy.1.xml:62
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "OPTIONS"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Opções"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:43 sss_usermod.8.xml:77
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<option>-a</option>,<option>--append-group</option> <replaceable>GROUPS</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:48
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Append this group to groups specified by the <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"a comma separated list of group names."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Acrescente este grupo para grupos especificados pelo parâmetro de "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<replaceable>GROUPS</replaceable>. O parâmetro de <replaceable>GROUPS</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> é uma lista separada por vírgulas de nomes de grupo."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:57 sss_usermod.8.xml:91
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<option>-r</option>,<option>--remove-group</option> <replaceable>GROUPS</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupmod.8.xml:62
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Remove this group from groups specified by the <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> parameter."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Remova este grupo de grupos especificados pelo parâmetro de "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<replaceable>GROUPS</replaceable>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:10 sssd.conf.5.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd.conf"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sssd.conf"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:11 sssd-ldap.5.xml:11 sssd-simple.5.xml:11 sssd-ipa.5.xml:11
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ad.5.xml:11 sssd-sudo.5.xml:11 sssd-krb5.5.xml:11 sssd-ifp.5.xml:11
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_rpcidmapd.5.xml:27 sssd-secrets.5.xml:11
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "5"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "5"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refmeta><refmiscinfo>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:12 sssd-ldap.5.xml:12 sssd-simple.5.xml:12 sssd-ipa.5.xml:12
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ad.5.xml:12 sssd-sudo.5.xml:12 sssd-krb5.5.xml:12 sssd-ifp.5.xml:12
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_rpcidmapd.5.xml:28 sssd-secrets.5.xml:12
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "File Formats and Conventions"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Formatos de ficheiros e convenções"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd.conf.5.xml:17
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "the configuration file for SSSD"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "o ficheiro de configuração para SSSD"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "FILE FORMAT"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "FORMATAR FICHEIRO"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:29
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>[section]</replaceable>\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>key</replaceable> = <replaceable>value</replaceable>\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<replaceable>key2</replaceable> = <replaceable>value2,value3</replaceable>\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher" "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:24
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The file has an ini-style syntax and consists of sections and parameters. A "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"section begins with the name of the section in square brackets and continues "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"until the next section begins. An example of section with single and multi-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"valued parameters: <placeholder type=\"programlisting\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:36
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The data types used are string (no quotes needed), integer and bool (with "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"values of <quote>TRUE/FALSE</quote>)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Os tipos de dados usados são cadeia de caracteres (sem aspas necessárias), "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"inteiro e bool (com valores de <quote>TRUE/FALSE</quote>)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.conf.5.xml:41
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"A line comment starts with a hash sign (<quote>#</quote>) or a semicolon "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"(<quote>;</quote>). Inline comments are not supported."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:47
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"All sections can have an optional <replaceable>description</replaceable> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"parameter. Its function is only as a label for the section."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Todas as seções podem ter um parâmetro opcional <replaceable>description</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable>. Sua função é apenas como um rótulo para a secção."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:53
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<filename>sssd.conf</filename> must be a regular file, owned by root and "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"only root may read from or write to the file."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<filename>sssd.conf</filename> deve ser um ficheiro regular, pertencente a "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"raiz e somente raiz pode ler ou gravar o arquivo."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#: sssd.conf.5.xml:59
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "CONFIGURATION SNIPPETS FROM INCLUDE DIRECTORY"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:62
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The configuration file <filename>sssd.conf</filename> will include "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"configuration snippets using the include directory <filename>conf.d</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"filename>. This feature is available if SSSD was compiled with libini "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"version 1.3.0 or later."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:69
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Any file placed in <filename>conf.d</filename> that ends in "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<quote><filename>.conf</filename></quote> and does not begin with a dot "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"(<quote>.</quote>) will be used together with <filename>sssd.conf</filename> "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"to configure SSSD."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:77
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The configuration snippets from <filename>conf.d</filename> have higher "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"priority than <filename>sssd.conf</filename> and will override "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<filename>sssd.conf</filename> when conflicts occur. If several snippets are "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"present in <filename>conf.d</filename>, then they are included in "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"alphabetical order (based on locale). Files included later have higher "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"priority. Numerical prefixes (<filename>01_snippet.conf</filename>, "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<filename>02_snippet.conf</filename> etc.) can help visualize the priority "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"(higher number means higher priority)."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:91
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"The snippet files require the same owner and permissions as <filename>sssd."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"conf</filename>. Which are by default root:root and 0600."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:98
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "GENERAL OPTIONS"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:100
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Following options are usable in more than one configuration sections."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:104
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Options usable in all sections"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:108
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_level (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:112
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "debug (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:115
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD 1.14 and later also includes the <replaceable>debug</replaceable> alias "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for <replaceable>debug_level</replaceable> as a convenience feature. If both "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are specified, the value of <replaceable>debug_level</replaceable> will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"used."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:125
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_timestamps (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:128
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Add a timestamp to the debug messages. If journald is enabled for SSSD "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"debug logging this option is ignored."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:133 sssd.conf.5.xml:713 sssd.conf.5.xml:1248
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1695 sssd-ldap.5.xml:1792 sssd-ldap.5.xml:1854
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2411 sssd-ldap.5.xml:2476 sssd-ldap.5.xml:2494
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:405 sssd-ipa.5.xml:440 sssd-ad.5.xml:201 sssd-ad.5.xml:299
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:836 sssd-ad.5.xml:955 sssd-krb5.5.xml:499
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: true"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:138
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "debug_microseconds (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "debug_microseconds (bool)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:141
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Add microseconds to the timestamp in debug messages. If journald is enabled "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"for SSSD debug logging this option is ignored."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:146 sssd.conf.5.xml:1202 sssd.conf.5.xml:2480
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:708 sssd-ldap.5.xml:1569 sssd-ldap.5.xml:1588
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1764 sssd-ldap.5.xml:2181 sssd-ipa.5.xml:139
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:211 sssd-ipa.5.xml:542 sssd-krb5.5.xml:266
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:300 sssd-krb5.5.xml:471
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: false"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "Padrão: false"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:106 sssd.conf.5.xml:157 sssd-ldap.5.xml:2219
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<placeholder type=\"variablelist\" id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:155
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Options usable in SERVICE and DOMAIN sections"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:159
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:162
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Timeout in seconds between heartbeats for this service. This is used to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ensure that the process is alive and capable of answering requests."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:167 sssd.conf.5.xml:1166 sssd.conf.5.xml:2496
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1440 include/ldap_id_mapping.xml:264
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 10"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "Padrão: 10"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:177
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SPECIAL SECTIONS"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SECÇÕES ESPECIAIS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:180
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The [sssd] section"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "A seção [SSSD]"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:189 sssd.conf.5.xml:2512
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Section parameters"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Parâmetros de secção"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:191
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "config_file_version (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "config_file_version (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:194
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Indicates what is the syntax of the config file. SSSD 0.6.0 and later use "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"version 2."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Indica qual é a sintaxe do arquivo config. SSSD 0.6.0 e posterior utilização "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"versão 2."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:200
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "services"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "serviços"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:203
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Comma separated list of services that are started when sssd itself starts."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Lista de serviços que são iniciados quando SSSD propriamente dito começa "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"separados por vírgulas."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:207
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Supported services: nss, pam <phrase condition=\"with_sudo\">, sudo</phrase> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<phrase condition=\"with_autofs\">, autofs</phrase> <phrase condition="
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"with_ssh\">, ssh</phrase> <phrase condition=\"with_pac_responder\">, pac</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"phrase> <phrase condition=\"with_ifp\">, ifp</phrase>"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:217 sssd.conf.5.xml:525
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "reconnection_retries (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "reconnection_retries (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:220 sssd.conf.5.xml:528
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Number of times services should attempt to reconnect in the event of a Data "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Provider crash or restart before they give up"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Número de vezes que os serviços devem tentar reconectar-se no caso de uma "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"falha do provedor de dados ou reiniciar antes de eles desistirem"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:225 sssd.conf.5.xml:533
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 3"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 3"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:230
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "domains"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "domínios"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:233
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"A domain is a database containing user information. SSSD can use more "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"domains at the same time, but at least one must be configured or SSSD won't "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"start. This parameter described the list of domains in the order you want "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"them to be queried. A domain name should only consist of alphanumeric ASCII "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"characters, dashes, dots and underscores."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:245 sssd.conf.5.xml:2129
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "re_expression (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "re_expression (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:248
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Default regular expression that describes how to parse the string containing "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"user name and domain into these components."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:253
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Each domain can have an individual regular expression configured. For some "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"ID providers there are also default regular expressions. See DOMAIN "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"SECTIONS for more info on these regular expressions."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:262 sssd.conf.5.xml:2180
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "full_name_format (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "full_name_format (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:265 sssd.conf.5.xml:2183
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"A <citerefentry> <refentrytitle>printf</refentrytitle> <manvolnum>3</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"manvolnum> </citerefentry>-compatible format that describes how to compose a "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"fully qualified name from user name and domain name components."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:276 sssd.conf.5.xml:2194
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%1$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:277 sssd.conf.5.xml:2195
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "user name"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:280 sssd.conf.5.xml:2198
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%2$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:283 sssd.conf.5.xml:2201
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "domain name as specified in the SSSD config file."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:289 sssd.conf.5.xml:2207
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "%3$s"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:292 sssd.conf.5.xml:2210
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"domain flat name. Mostly usable for Active Directory domains, both directly "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"configured or discovered via IPA trusts."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:273 sssd.conf.5.xml:2191
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"The following expansions are supported: <placeholder type=\"variablelist\" "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:302
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Each domain can have an individual format string configured. see DOMAIN "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"SECTIONS for more info on this option."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:308
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "try_inotify (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "try_inotify (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:311
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SSSD monitors the state of resolv.conf to identify when it needs to update "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"its internal DNS resolver. By default, we will attempt to use inotify for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"this, and will fall back to polling resolv.conf every five seconds if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"inotify cannot be used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:319
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"There are some limited situations where it is preferred that we should skip "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"even trying to use inotify. In these rare cases, this option should be set "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to 'false'"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:325
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: true on platforms where inotify is supported. False on other "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"platforms."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:329
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Note: this option will have no effect on platforms where inotify is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"unavailable. On these platforms, polling will always be used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:336
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_rcache_dir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_rcache_dir (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:339
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Directory on the filesystem where SSSD should store Kerberos replay cache "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"files."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:343
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This option accepts a special value __LIBKRB5_DEFAULTS__ that will instruct "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SSSD to let libkrb5 decide the appropriate location for the replay cache."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:349
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: Distribution-specific and specified at build-time. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(__LIBKRB5_DEFAULTS__ if not configured)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:356
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "user (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:359
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The user to drop the privileges to where appropriate to avoid running as the "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"root user."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:364
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: not set, process will run as root"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:369
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "default_domain_suffix (string)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:372
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"This string will be used as a default domain name for all names without a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain name component. The main use case is environments where the primary "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain is intended for managing host policies and all users are located in a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"trusted domain. The option allows those users to log in just with their "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"user name without giving a domain name as well."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:382
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Please note that if this option is set all users from the primary domain "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"have to use their fully qualified name, e.g. user@domain.name, to log in. "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Setting this option changes default of use_fully_qualified_names to True. It "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"is not allowed to use this option together with use_fully_qualified_names "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"set to False."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:391 sssd-ldap.5.xml:679 sssd-ldap.5.xml:1528
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1540 sssd-ldap.5.xml:1622 sssd-ad.5.xml:641
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:716 sssd-krb5.5.xml:410 sssd-krb5.5.xml:556
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:260 include/ldap_id_mapping.xml:205
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/ldap_id_mapping.xml:216
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: not set"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:396
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "override_space (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:399
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This parameter will replace spaces (space bar) with the given character for "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"user and group names. e.g. (_). User name &quot;john doe&quot; will be "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"&quot;john_doe&quot; This feature was added to help compatibility with shell "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"scripts that have difficulty handling spaces, due to the default field "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"separator in the shell."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:408
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Please note it is a configuration error to use a replacement character that "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"might be used in user or group names. If a name contains the replacement "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"character SSSD tries to return the unmodified name but in general the result "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"of a lookup is undefined."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:416
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: not set (spaces will not be replaced)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:421
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "re_expression (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "certificate_verification (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "re_expression (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:429
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "no_ocsp"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:431
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Disables Online Certificate Status Protocol (OCSP) checks. This might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"needed if the OCSP servers defined in the certificate are not reachable from "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the client."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:439
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "no_verification"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:441
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Disables verification completely. This option should only be used for "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"testing."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:447
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ocsp_default_responder=URL"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:449
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Sets the OCSP default responder which should be used instead of the one "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"mentioned in the certificate. URL must be replaced with the URL of the OCSP "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"default responder e.g. http://example.com:80/ocsp."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:455
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option must be used together with ocsp_default_responder_signing_cert."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:463
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ocsp_default_responder_signing_cert=NAME"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:465
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The nickname of the cert to trust (expected) to sign the OCSP responses. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The certificate with the given nickname must be availble in the systems NSS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"database."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:470
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "This option must be used together with ocsp_default_responder."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:424
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"With this parameter the certificate verification can be tuned with a comma "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"separated list of options. Supported options are: <placeholder type="
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"\"variablelist\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:477
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Unknown options are reported but ignored."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:480
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#, fuzzy
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#| msgid "Default: not set, i.e. the TGT is not renewable"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "Default: not set, i.e. do not restrict certificate verification"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr "Padrão: não definido, ou seja, o TGT não é renovável"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:486
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "ldap_sasl_canonicalize (boolean)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "disable_netlink (boolean)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "ldap_sasl_canonicalize (boolean)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:489
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"SSSD hooks into the netlink interface to monitor changes to routes, "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"addresses, links and trigger certain actions."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:494
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The SSSD state changes caused by netlink events may be undesirable and can "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"be disabled by setting this option to 'true'"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:499
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: false (netlink changes are detected)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssd.conf.5.xml:182
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Individual pieces of SSSD functionality are provided by special SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"services that are started and stopped together with SSSD. The services are "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"managed by a special service frequently called <quote>monitor</quote>. The "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>[sssd]</quote> section is used to configure the monitor as well as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"some other important options like the identity domains. <placeholder type="
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\"variablelist\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:510
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SERVICES SECTIONS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:512
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Settings that can be used to configure different services are described in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"this section. They should reside in the [<replaceable>$NAME</replaceable>] "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"section, for example, for NSS service, the section would be <quote>[nss]</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"quote>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:519
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "General service configuration options"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:521
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "These options can be used to configure any service."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:538
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "fd_limit"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:541
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"This option specifies the maximum number of file descriptors that may be "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"opened at one time by this SSSD process. On systems where SSSD is granted "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the CAP_SYS_RESOURCE capability, this will be an absolute setting. On "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"systems without this capability, the resulting value will be the lower value "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"of this or the limits.conf \"hard\" limit."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:550
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: 8192 (or limits.conf \"hard\" limit)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:555
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "client_idle_timeout"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:558
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option specifies the number of seconds that a client of an SSSD process "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"can hold onto a file descriptor without communicating on it. This value is "
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozek"limited in order to avoid resource exhaustion on the system."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:565 sssd.conf.5.xml:597 sssd.conf.5.xml:844
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1036 sssd-ldap.5.xml:1267
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 60"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr "Padrão: 60"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:570
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "offline_timeout (integer)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:573
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"When SSSD switches to offline mode the amount of time before it tries to go "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"back online will increase based upon the time spent disconnected. This "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"value is in seconds and calculated by the following:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:580
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "offline_timeout + random_offset"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:583
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The random offset can increment up to 30 seconds. After each unsuccessful "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attempt to go online, the new interval is recalculated by the following:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:588
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "new_interval = old_interval*2 + random_offset"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:591
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Note that the maximum length of each interval is currently limited to one "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"hour. If the calculated length of new_interval is greater than an hour, it "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"will be forced to one hour."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:605
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "NSS configuration options"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:607
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"These options can be used to configure the Name Service Switch (NSS) service."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:612
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "enum_cache_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:615
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"How many seconds should nss_sss cache enumerations (requests for info about "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"all users)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:619
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 120"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:624
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "entry_cache_nowait_percentage (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:627
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The entry cache can be set to automatically update entries in the background "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"if they are requested beyond a percentage of the entry_cache_timeout value "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"for the domain."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:633
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For example, if the domain's entry_cache_timeout is set to 30s and "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"entry_cache_nowait_percentage is set to 50 (percent), entries that come in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"after 15 seconds past the last cache update will be returned immediately, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"but the SSSD will go and update the cache on its own, so that future "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"requests will not need to block waiting for a cache update."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:643
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Valid values for this option are 0-99 and represent a percentage of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"entry_cache_timeout for each domain. For performance reasons, this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"percentage will never reduce the nowait timeout to less than 10 seconds. (0 "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"disables this feature)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:651
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 50"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 50"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:656
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "entry_negative_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:659
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies for how many seconds nss_sss should cache negative cache hits "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(that is, queries for invalid database entries, like nonexistent ones) "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"before asking the back end again."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:665 sssd.conf.5.xml:1226
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 15"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:670
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "ldap_network_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "local_negative_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_network_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:673
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies for how many seconds nss_sss should keep local users and groups in "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"negative cache before trying to look it up in the back end again."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:678 sssd.conf.5.xml:1024 sssd.conf.5.xml:2430 sssd.8.xml:79
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 0"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:683
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "filter_users, filter_groups (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:686
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Exclude certain users or groups from being fetched from the sss NSS "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"database. This is particularly useful for system accounts. This option can "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"also be set per-domain or include fully-qualified names to filter only users "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from the particular domain."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:693
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: The filter_groups option doesn't affect inheritance of nested group "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"members, since filtering happens after they are propagated for returning via "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NSS. E.g. a group having a member group filtered out will still have the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"member users of the latter listed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:701
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: root"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:706
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "filter_users_in_groups (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:709
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If you want filtered user still be group members set this option to false."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:720
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "fallback_homedir (string)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:723
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Set a default template for a user's home directory if one is not specified "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"explicitly by the domain's data provider."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:728
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"The available values for this option are the same as for override_homedir."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:734
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fallback_homedir = /home/%u\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek" "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:732 sssd.conf.5.xml:1103 sssd.conf.5.xml:1122
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:539 include/override_homedir.xml:55
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "example: <placeholder type=\"programlisting\" id=\"0\"/>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:738
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: not set (no substitution for unset home directories)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:744
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "override_shell (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:747
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Override the login shell for all users. This option supersedes any other "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"shell options if it takes effect and can be set either in the [nss] section "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"or per-domain."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:753
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Default: not set (SSSD will use the value retrieved from LDAP)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:759
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "allowed_shells (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "allowed_shells (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:762
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Restrict user shell to one of the listed values. The order of evaluation is:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:765
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "1. If the shell is present in <quote>/etc/shells</quote>, it is used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:769
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"2. If the shell is in the allowed_shells list but not in <quote>/etc/shells</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"quote>, use the value of the shell_fallback parameter."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:774
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"3. If the shell is not in the allowed_shells list and not in <quote>/etc/"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"shells</quote>, a nologin shell is used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:779
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The wildcard (*) can be used to allow any shell."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:782
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The (*) is useful if you want to use shell_fallback in case that user's "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"shell is not in <quote>/etc/shells</quote> and maintaining list of all "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"allowed shells in allowed_shells would be to much overhead."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:789
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "An empty string for shell is passed as-is to libc."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:792
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The <quote>/etc/shells</quote> is only read on SSSD start up, which means "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"that a restart of the SSSD is required in case a new shell is installed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:796
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: Not set. The user shell is automatically used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:801
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "vetoed_shells (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "vetoed_shells (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:804
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Replace any instance of these shells with the shell_fallback"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:809
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "shell_fallback (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "shell_fallback (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:812
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The default shell to use if an allowed shell is not installed on the machine."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:816
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: /bin/sh"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: /bin/sh"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:821
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "default_shell"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:824
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The default shell to use if the provider does not return one during lookup. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option can be specified globally in the [nss] section or per-domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:830
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Default: not set (Return NULL if no shell is specified and rely on libc to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"substitute something sensible when necessary, usually /bin/sh)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:837 sssd.conf.5.xml:1029
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "get_domains_timeout (int)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:840 sssd.conf.5.xml:1032
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies time in seconds for which the list of subdomains will be "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"considered valid."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:849
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "memcache_timeout (int)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:852
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Specifies time in seconds for which records in the in-memory cache will be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"valid."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:856 sssd.conf.5.xml:1340 sssd-ldap.5.xml:722
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: 300"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "Padrão: 300"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:859
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"NOTE: If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"client applications will not use the fast in-memory cache."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:867 sssd-ifp.5.xml:74
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "user_attributes (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:870
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Some of the additional NSS responder requests can return more attributes "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"than just the POSIX ones defined by the NSS interface. The list of "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"attributes is controlled by this option. It is handled the same way as the "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<quote>user_attributes</quote> option of the InfoPipe responder (see "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"manvolnum> </citerefentry> for details) but with no default values."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:883
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"To make configuration more easy the NSS responder will check the InfoPipe "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"option if it is not set for the NSS responder."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:888
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: not set, fallback to InfoPipe option"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:895
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "PAM configuration options"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:897
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"These options can be used to configure the Pluggable Authentication Module "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(PAM) service."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:902
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "offline_credentials_expiration (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:905
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If the authentication provider is offline, how long should we allow cached "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"logins (in days since the last successful online login)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:910 sssd.conf.5.xml:923
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 0 (No limit)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:916
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "offline_failed_login_attempts (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:919
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If the authentication provider is offline, how many failed login attempts "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are allowed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:929
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "offline_failed_login_delay (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:932
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The time in minutes which has to pass after offline_failed_login_attempts "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"has been reached before a new login attempt is possible."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:937
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If set to 0 the user cannot authenticate offline if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"offline_failed_login_attempts has been reached. Only a successful online "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"authentication can enable offline authentication again."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:943 sssd.conf.5.xml:996
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 5"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:949
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "pam_verbosity (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:952
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Controls what kind of messages are shown to the user during authentication. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The higher the number to more messages are displayed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:957
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Currently sssd supports the following values:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:960
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>0</emphasis>: do not show any message"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:963
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>1</emphasis>: show only important messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:967
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>2</emphasis>: show informational messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:970
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>3</emphasis>: show all messages and debug information"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:974 sssd.8.xml:63
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 1"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 1"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:979
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "pam_id_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "pam_id_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:982
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For any PAM request while SSSD is online, the SSSD will attempt to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"immediately update the cached identity information for the user in order to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"ensure that authentication takes place with the latest information."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:988
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"A complete PAM conversation may perform multiple PAM requests, such as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"account management and session opening. This option controls (on a per-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"client-application basis) how long (in seconds) we can cache the identity "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"information to avoid excessive round-trips to the identity provider."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1002
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "pam_pwd_expiration_warning (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "pam_pwd_expiration_warning (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1005 sssd.conf.5.xml:1655
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Display a warning N days before the password expires."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1008
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that the backend server has to provide information about the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"expiration time of the password. If this information is missing, sssd "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"cannot display a warning."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1014 sssd.conf.5.xml:1658
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"If zero is set, then this filter is not applied, i.e. if the expiration "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"warning was received from backend server, it will automatically be displayed."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1019
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"This setting can be overridden by setting <emphasis>pwd_expiration_warning</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"emphasis> for a particular domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1041
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "pam_trusted_users (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1044
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"allowed to run PAM conversations against trusted domains. Users not "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"included in this list can only access domains marked as public with "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>pam_public_domains</quote>. User names are resolved to UIDs at "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"startup."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1054
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: All users are considered trusted by default"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1058
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Please note that UID 0 is always allowed to access the PAM responder even in "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"case it is not in the pam_trusted_users list."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1065
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "pam_public_domains (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1068
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Specifies the comma-separated list of domain names that are accessible even "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"to untrusted users."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1072
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Two special values for pam_public_domains option are defined:"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1076
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"all (Untrusted users are allowed to access all domains in PAM responder.)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1080
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"none (Untrusted users are not allowed to access any domains PAM in "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"responder.)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1084 sssd.conf.5.xml:1109 sssd.conf.5.xml:1128
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1452 sssd.conf.5.xml:2366 sssd-ldap.5.xml:1823
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: none"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "Padrão: none"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1089
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "pam_account_expired_message (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1092
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Allows a custom expiration message to be set, replacing the default "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"'Permission denied' message."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1097
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Please be aware that message is only printed for the SSH service "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"unless pam_verbostiy is set to 3 (show all messages and debug information)."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1105
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"pam_account_expired_message = Account expired, please contact help desk.\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1114
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_account_locked_message (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1117
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Allows a custom lockout message to be set, replacing the default 'Permission "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"denied' message."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1124
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"pam_account_locked_message = Account locked, please contact help desk.\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1133
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "enumerate (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_cert_auth (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "enumerate (bool)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1136
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Enable certificate based Smartcard authentication. Since this requires "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"additional communication with the Smartcard which will delay the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"authentication process this option is disabled by default."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1142 sssd-ldap.5.xml:1051 sssd-ldap.5.xml:1078
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1369 sssd-ldap.5.xml:1390 sssd-ldap.5.xml:1896
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:244
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: False"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1147
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "ipa_hbac_search_base (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pam_cert_db_path (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ipa_hbac_search_base (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1150
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The path to the certificate database which contain the PKCS#11 modules to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"access the Smartcard."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1154
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: /etc/pki/nssdb (NSS version)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1159
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "pam_id_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "p11_child_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "pam_id_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1162
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "How many seconds will pam_sss wait for p11_child to finish."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1175
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "SUDO configuration options"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1177
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"These options can be used to configure the sudo service. The detailed "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"instructions for configuration of <citerefentry> <refentrytitle>sudo</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to work with "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"</citerefentry> are in the manual page <citerefentry> <refentrytitle>sssd-"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"sudo</refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1194
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "sudo_timed (bool)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1197
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Whether or not to evaluate the sudoNotBefore and sudoNotAfter attributes "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"that implement time-dependent sudoers entries."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1210
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "AUTOFS configuration options"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1212
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "These options can be used to configure the autofs service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1216
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "autofs_negative_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1219
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Specifies for how many seconds should the autofs responder negative cache "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"hits (that is, queries for invalid map entries, like nonexistent ones) "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"before asking the back end again."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1235
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "SSH configuration options"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1237
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "These options can be used to configure the SSH service."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1241
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ssh_hash_known_hosts (bool)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1244
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
45db68ae27147955a4be4c2c772041824c0dc00fStephen Gallagher"Whether or not to hash host names and addresses in the managed known_hosts "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"file."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1253
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ssh_known_hosts_timeout (integer)"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1256
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"How many seconds to keep a host in the managed known_hosts file after its "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"host keys were requested."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1260
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 180"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1265
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "mail_dir (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ca_db (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "mail_dir (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1268
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Path to a storage of trusted CA certificates. The option is used to validate "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"user certificates before deriving public ssh keys from them."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1273
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "Default: /etc/krb5.keytab"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: /etc/pki/nssdb"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "Padrão: /etc/krb5.keytab"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1281
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "PAC responder configuration options"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1283
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"The PAC responder works together with the authorization data plugin for MIT "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Kerberos sssd_pac_plugin.so and a sub-domain provider. The plugin sends the "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PAC data during a GSSAPI authentication to the PAC responder. The sub-domain "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"provider collects domain SID and ID ranges of the domain the client is "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"joined to and of remote trusted domains from the local domain controller. "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If the PAC is decoded and evaluated some of the following operations are "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"done:"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1292
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If the remote user does not exist in the cache, it is created. The uid is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"determined with the help of the SID, trusted domains will have UPGs and the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"gid will have the same value as the uid. The home directory is set based on "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the subdomain_homedir parameter. The shell will be empty by default, i.e. "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the system defaults are used, but can be overwritten with the default_shell "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"parameter."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1300
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"If there are SIDs of groups from domains sssd knows about, the user will be "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"added to those groups."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1306
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "These options can be used to configure the PAC responder."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1310 sssd-ifp.5.xml:50
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "allowed_uids (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1313
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"allowed to access the PAC responder. User names are resolved to UIDs at "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"startup."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1319
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: 0 (only the root user is allowed to access the PAC responder)"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1323
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Please note that although the UID 0 is used as the default it will be "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"overwritten with this option. If you still want to allow the root user to "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"access the PAC responder, which would be the typical case, you have to add 0 "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"to the list of allowed UIDs as well."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1332
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "pam_id_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "pac_lifetime (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "pam_id_timeout (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1335
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Lifetime of the PAC entry in seconds. As long as the PAC is valid the PAC "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"data can be used to determine the group memberships of a user."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1350
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "DOMAIN SECTIONS"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SECÇÕES DE DOMÍNIO"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1357
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "min_id,max_id (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "min_id,max_id (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1360
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"UID and GID limits for the domain. If a domain contains an entry that is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"outside these limits, it is ignored."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1365
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For users, this affects the primary GID limit. The user will not be returned "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to NSS if either the UID or the primary GID is outside the range. For non-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"primary group memberships, those that are in range will be reported as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"expected."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1372
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"These ID limits affect even saving entries to cache, not only returning them "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"by name or ID."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1376
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 1 for min_id, 0 (no limit) for max_id"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 1 para min_id, 0 (sem limite) para max_id"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1382
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "enumerate (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "enumerate (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1385
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Determines if a domain can be enumerated. This parameter can have one of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"following values:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1389
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "TRUE = Users and groups are enumerated"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1392
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "FALSE = No enumerations for this domain"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1395 sssd.conf.5.xml:1610 sssd.conf.5.xml:1777
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: FALSE"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: FALSE"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1398
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Note: Enabling enumeration has a moderate performance impact on SSSD while "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"enumeration is running. It may take up to several minutes after SSSD startup "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to fully complete enumerations. During this time, individual requests for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"information will go directly to LDAP, though it may be slow, due to the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"heavy enumeration processing. Saving a large number of entries to cache "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"after the enumeration completes might also be CPU intensive as the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"memberships have to be recomputed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1411
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"While the first enumeration is running, requests for the complete user or "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"group lists may return no results until it completes."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1416
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Further, enabling enumeration may increase the time necessary to detect "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"network disconnection, as longer timeouts are required to ensure that "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"enumeration lookups are completed successfully. For more information, refer "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to the man pages for the specific id_provider in use."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1424
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"For the reasons cited above, enabling enumeration is not recommended, "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"especially in large environments."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1432
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "subdomain_enumerate (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1439
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "all"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1440
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "All discovered trusted domains will be enumerated"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1443
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "none"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1444
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "No discovered trusted domains will be enumerated"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1435
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Whether any of autodetected trusted domains should be enumerated. The "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"supported values are: <placeholder type=\"variablelist\" id=\"0\"/> "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Optionally, a list of one or more domain names can enable enumeration just "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"for these trusted domains."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1458
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "entry_cache_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "entry_cache_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1461
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"How many seconds should nss_sss consider entries valid before asking the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"backend again"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1465
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The cache expiration timestamps are stored as attributes of individual "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"objects in the cache. Therefore, changing the cache timeout only has effect "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"for newly added or expired entries. You should run the <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> tool in order to force refresh of entries that have already "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"been cached."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1478
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 5400"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 5400"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1484
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_user_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1487
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider user entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1491 sssd.conf.5.xml:1504 sssd.conf.5.xml:1517
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1530 sssd.conf.5.xml:1543 sssd.conf.5.xml:1557
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1571
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: entry_cache_timeout"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1497
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_group_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1500
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider group entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1510
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_netgroup_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1513
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider netgroup entries valid before "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"asking the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1523
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "entry_cache_service_timeout (integer)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1526
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"How many seconds should nss_sss consider service entries valid before asking "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the backend again"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1536
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "entry_cache_sudo_timeout (integer)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1539
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds should sudo consider rules valid before asking the backend "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"again"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1549
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "entry_cache_autofs_timeout (integer)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1552
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"How many seconds should the autofs service consider automounter maps valid "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"before asking the backend again"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1563
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "entry_cache_ssh_host_timeout (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1566
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"How many seconds to keep a host ssh key after refresh. IE how long to cache "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the host key for."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1577
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "refresh_expired_interval (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1580
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies how many seconds SSSD has to wait before triggering a background "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"refresh task which will refresh all expired or nearly expired records."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1585
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The background refresh will process users, groups and netgroups in the cache."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1589
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "You can consider setting this value to 3/4 * entry_cache_timeout."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1593 sssd-ldap.5.xml:746 sssd-ipa.5.xml:227
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Default: 0 (disabled)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1599
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "cache_credentials (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "cache_credentials (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1602
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Determines if user credentials are also cached in the local LDB cache"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1606
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "User credentials are stored in a SHA512 hash, not in plaintext"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1616
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "cache_credentials_minimal_first_factor_length (int)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1619
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"If 2-Factor-Authentication (2FA) is used and credentials should be saved "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"this value determines the minimal length the first authentication factor "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"(long term password) must have to be saved as SHA512 hash into the cache."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1626
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"This should avoid that the short PINs of a PIN based 2FA scheme are saved in "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the cache which would make them easy targets for brute-force attacks."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1631
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: 8"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1637
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "account_cache_expiration (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "account_cache_expiration (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1640
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Number of days entries are left in cache after last successful login before "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"being removed during a cleanup of the cache. 0 means keep forever. The "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"value of this parameter must be greater than or equal to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"offline_credentials_expiration."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1647
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 0 (unlimited)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 0 (ilimitado)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1652
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "pwd_expiration_warning (integer)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1663
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Please note that the backend server has to provide information about the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"expiration time of the password. If this information is missing, sssd "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"cannot display a warning. Also an auth provider has to be configured for the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"backend."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1670
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: 7 (Kerberos), 0 (LDAP)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1676
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "id_provider (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "id_provider (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1679
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The identification provider used for the domain. Supported ID providers are:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1683
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "<quote>proxy</quote>: Support a legacy NSS provider"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1686 sssd.conf.5.xml:1823
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<quote>local</quote>: SSSD internal provider for local users"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1690
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ldap</quote>: LDAP provider. See <citerefentry> <refentrytitle>sssd-"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"information on configuring LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1698 sssd.conf.5.xml:1803 sssd.conf.5.xml:1858
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1921
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ipa</quote>: FreeIPA and Red Hat Enterprise Identity Management "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"provider. See <citerefentry> <refentrytitle>sssd-ipa</refentrytitle> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"FreeIPA."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1707 sssd.conf.5.xml:1812 sssd.conf.5.xml:1867
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1930
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ad</quote>: Active Directory provider. See <citerefentry> "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry> for more information on configuring Active Directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1718
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "use_fully_qualified_names (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "use_fully_qualified_names (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1721
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Use the full name and domain (as formatted by the domain's full_name_format) "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"as the user's login name reported to NSS."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1726
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If set to TRUE, all requests to this domain must use fully qualified names. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For example, if used in LOCAL domain that contains a \"test\" user, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>getent passwd test</command> wouldn't find the user while "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>getent passwd test@LOCAL</command> would."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1734
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"NOTE: This option has no effect on netgroup lookups due to their tendency to "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"include nested netgroups without qualified names. For netgroups, all domains "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"will be searched when an unqualified name is requested."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1741
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: FALSE (TRUE if default_domain_suffix is used)"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1747
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ignore_group_members (bool)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1750
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Do not return group members for group lookups."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1753
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If set to TRUE, the group membership attribute is not requested from the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap server, and group members are not returned when processing group lookup "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"calls, such as <citerefentry> <refentrytitle>getgrnam</refentrytitle> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<manvolnum>3</manvolnum> </citerefentry> or <citerefentry> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<refentrytitle>getgrgid</refentrytitle> <manvolnum>3</manvolnum> </"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"citerefentry>. As an effect, <quote>getent group $groupname</quote> would "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"return the requested group as if it was empty."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1771
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Enabling this option can also make access provider checks for group "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"membership significantly faster, especially for groups containing many "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"members."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1782
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "auth_provider (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "auth_provider (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1785
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The authentication provider used for the domain. Supported auth providers "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1789 sssd.conf.5.xml:1851
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>ldap</quote> for native LDAP authentication. See <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> for more information on configuring LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1796
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>krb5</quote> for Kerberos authentication. See <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> for more information on configuring Kerberos."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1820
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>proxy</quote> for relaying authentication to some other PAM target."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1827
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<quote>none</quote> disables authentication explicitly."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1830
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can handle "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authentication requests."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1836
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "access_provider (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "access_provider (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1839
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The access control provider used for the domain. There are two built-in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"access providers (in addition to any included in installed backends) "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Internal special providers are:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1845
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>permit</quote> always allow access. It's the only permitted access "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"provider for a local domain."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1848
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<quote>deny</quote> always deny access."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1875
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>simple</quote> access control based on access or deny lists. See "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd-simple</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum></citerefentry> for more information on configuring the simple "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"access module."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1882
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>krb5</quote>: .k5login based access control. See <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum></"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> for more information on configuring Kerberos."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1889
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<quote>proxy</quote> for relaying access control to another PAM module."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1892
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <quote>permit</quote>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1897
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "chpass_provider (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1900
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The provider which should handle change password operations for the domain. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Supported change password providers are:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1905
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>ldap</quote> to change a password stored in a LDAP server. See "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> for more information on configuring LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1913
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>krb5</quote> to change the Kerberos password. See <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> for more information on configuring Kerberos."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1938
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>proxy</quote> for relaying password changes to some other PAM target."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1942
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<quote>none</quote> disallows password changes explicitly."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1945
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: <quote>auth_provider</quote> is used if it is set and can handle "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"change password requests."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1952
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "sudo_provider (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1955
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The SUDO provider used for the domain. Supported SUDO providers are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1959
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<quote>ldap</quote> for rules stored in LDAP. See <citerefentry> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"citerefentry> for more information on configuring LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1967
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>ipa</quote> the same as <quote>ldap</quote> but with IPA default "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"settings."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1971
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>ad</quote> the same as <quote>ldap</quote> but with AD default "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"settings."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1975
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<quote>none</quote> disables SUDO explicitly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1978 sssd.conf.5.xml:2056 sssd.conf.5.xml:2097
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2122
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: The value of <quote>id_provider</quote> is used if it is set."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1982
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The detailed instructions for configuration of sudo_provider are in the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>. There are many configuration "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"options that can be used to adjust the behavior. Please refer to "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"\"ldap_sudo_*\" in <citerefentry> <refentrytitle>sssd-ldap</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1999
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "selinux_provider (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2002
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The provider which should handle loading of selinux settings. Note that this "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"provider will be called right after access provider ends. Supported selinux "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"providers are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2008
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<quote>ipa</quote> to load selinux settings from an IPA server. See "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2016
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "<quote>none</quote> disallows fetching selinux settings explicitly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2019
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Default: <quote>id_provider</quote> is used if it is set and can handle "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"selinux loading requests."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2025
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "subdomains_provider (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2028
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The provider which should handle fetching of subdomains. This value should "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"be always the same as id_provider. Supported subdomain providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2034
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load a list of subdomains from an IPA server. See "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2043
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<quote>ad</quote> to load a list of subdomains from an Active Directory "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"server. See <citerefentry> <refentrytitle>sssd-ad</refentrytitle> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry> for more information on configuring "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"the AD provider."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2052
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disallows fetching subdomains explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2063
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "autofs_provider (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2066
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The autofs provider used for the domain. Supported autofs providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2070
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap</quote> to load maps stored in LDAP. See <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more information on configuring LDAP."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2077
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load maps stored in an IPA server. See <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2085
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ad</quote> to load maps stored in an AD server. See <citerefentry> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle> <manvolnum>5</manvolnum> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"citerefentry> for more information on configuring the AD provider."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2094
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disables autofs explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2104
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "hostid_provider (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2107
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The provider used for retrieving host identity information. Supported "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"hostid providers are:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2111
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ipa</quote> to load host identity stored in an IPA server. See "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<citerefentry> <refentrytitle>sssd-ipa</refentrytitle> <manvolnum>5</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"manvolnum> </citerefentry> for more information on configuring IPA."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2119
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<quote>none</quote> disables hostid explicitly."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2132
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Regular expression for this domain that describes how to parse the string "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"containing user name and domain into these components. The \"domain\" can "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"match either the SSSD configuration domain name, or, in the case of IPA "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"trust subdomains and Active Directory domains, the flat (NetBIOS) name of "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"the domain."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2141
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Default for the AD and IPA provider: <quote>(((?P&lt;domain&gt;[^\\\\]+)\\"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"\\(?P&lt;name&gt;.+$))|((?P&lt;name&gt;[^@]+)@(?P&lt;domain&gt;.+$))|(^(?"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"P&lt;name&gt;[^@\\\\]+)$))</quote> which allows three different styles for "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"user names:"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2146
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "username"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2149
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "username@domain.name"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2152
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "domain\\username"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2155
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"While the first two correspond to the general default the third one is "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"introduced to allow easy integration of users from Windows domains."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2160
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Default: <quote>(?P&lt;name&gt;[^@]+)@?(?P&lt;domain&gt;[^@]*$)</quote> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"which translates to \"the name is everything up to the <quote>@</quote> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"sign, the domain everything after that\""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2166
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PLEASE NOTE: the support for non-unique named subpatterns is not available "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"on all platforms (e.g. RHEL5 and SLES10). Only platforms with libpcre "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"version 7 or higher can support non-unique named subpatterns."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2173
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"PLEASE NOTE ALSO: older version of libpcre only support the Python syntax (?"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"P&lt;name&gt;) to label subpatterns."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2220
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: <quote>%1$s@%2$s</quote>."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr "Default: <quote>%1$s@%2$s</quote>."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2226
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "lookup_family_order (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2229
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Provides the ability to select preferred address family to use when "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"performing DNS lookups."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2233
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Supported values:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2236
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipv4_first: Try looking up IPv4 address, if that fails, try IPv6"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2239
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipv4_only: Only attempt to resolve hostnames to IPv4 addresses."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2242
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipv6_first: Try looking up IPv6 address, if that fails, try IPv4"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2245
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipv6_only: Only attempt to resolve hostnames to IPv6 addresses."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2248
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: ipv4_first"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Default: ipv4_first"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2254
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "dns_resolver_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "dns_resolver_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2257
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Defines the amount of time (in seconds) to wait for a reply from the DNS "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"resolver before assuming that it is unreachable. If this timeout is reached, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the domain will continue to operate in offline mode."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2263 sssd-ldap.5.xml:1251 sssd-ldap.5.xml:1293
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1311 sssd-krb5.5.xml:248
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "Default: 6"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr "Padrão: 6"
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2269
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "dns_discovery_domain (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "dns_discovery_domain (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2272
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If service discovery is used in the back end, specifies the domain part of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the service discovery DNS query."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2276
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: Use the domain part of machine's hostname"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2282
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "override_gid (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "override_gid (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2285
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Override the primary GID value with the one specified."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2291
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "case_sensitive (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2299
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "True"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2302
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Case sensitive. This value is invalid for AD provider."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2308
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "False"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2310
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Case insensitive."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2314
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Preserving"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2317
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Same as False (case insensitive), but does not lowercase names in the result "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"of NSS operations. Note that name aliases (and in case of services also "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"protocol names) are still lowercased in the output."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2294
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Treat user and group names as case sensitive. At the moment, this option is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"not supported in the local provider. Possible option values are: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2329
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: True (False for AD provider)"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2335
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "subdomain_inherit (string)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2338
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Specifies a list of configuration parameters that should be inherited by a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"subdomain. Please note that only selected parameters can be inherited. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Currently the following options can be inherited:"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2344
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ignore_group_members"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2347
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_purge_cache_timeout"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2350 sssd-ldap.5.xml:1084
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_use_tokengroups"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2353
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_user_principal"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2356
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"ldap_krb5_keytab (the value of krb5_keytab will be used if ldap_krb5_keytab "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is not set explicitly)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2362
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"subdomain_inherit = ldap_purge_cache_timeout\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2360 sssd-secrets.5.xml:293
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Example: <placeholder type=\"programlisting\" id=\"0\"/>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2369
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Note: This option only works with the IPA and AD provider."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2376
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "subdomain_homedir (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2387
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%F"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2388
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "flat (NetBIOS) name of a subdomain."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2379
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Use this homedir as default value for all subdomains within this domain in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"IPA AD trust. See <emphasis>override_homedir</emphasis> for info about "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"possible values. In addition to those, the expansion below can only be used "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"with <emphasis>subdomain_homedir</emphasis>. <placeholder type="
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\"variablelist\" id=\"0\"/>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2393
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The value can be overridden by <emphasis>override_homedir</emphasis> option."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2397
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: <filename>/home/%d/%u</filename>"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2402
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "realmd_tags (string)"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2405
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Various tags stored by the realmd configuration service for this domain."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2411
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#, fuzzy
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#| msgid "krb5_auth_timeout (integer)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid "cached_auth_timeout (int)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr "krb5_auth_timeout (integer)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2414
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Specifies time in seconds since last successful online authentication for "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"which user will be authenticated using cached credentials while SSSD is in "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"the online mode."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2420
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid "Special value 0 implies that this feature is disabled."
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2424
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgid ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"Please note that if <quote>cached_auth_timeout</quote> is longer than "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>pam_id_timeout</quote> then the back end could be called to handle "
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek"<quote>initgroups.</quote>"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:1352
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"These configuration options can be present in a domain configuration "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"section, that is, in a section called <quote>[domain/<replaceable>NAME</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>]</quote> <placeholder type=\"variablelist\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2442
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "proxy_pam_target (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "proxy_pam_target (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2445
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The proxy target PAM proxies to."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2448
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: not set by default, you have to take an existing pam configuration "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"or create a new one and add the service name here."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2456
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "proxy_lib_name (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "proxy_lib_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2459
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The name of the NSS library to use in proxy domains. The NSS functions "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"searched for in the library are in the form of _nss_$(libName)_$(function), "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"for example _nss_files_getpwent."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2469
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "proxy_fast_alias (boolean)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2472
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When a user or group is looked up by name in the proxy provider, a second "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"lookup by ID is performed to \"canonicalize\" the name in case the requested "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"name was an alias. Setting this option to true would cause the SSSD to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"perform the ID lookup from cache for performance reasons."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2486
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "min_id,max_id (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "proxy_max_children (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "min_id,max_id (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2489
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"This option specifies the number of pre-forked proxy children. It is useful "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"for high-load SSSD environments where sssd may run out of available child "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"slots, which would cause some issues due to the requests being queued."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2438
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Options valid for proxy domains. <placeholder type=\"variablelist\" id="
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2505
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The local domain section"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "A secção de domínio local"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2507
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This section contains settings for domain that stores users and groups in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"SSSD native database, that is, a domain that uses "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>id_provider=local</replaceable>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2514
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "default_shell (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "default_shell (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2517
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The default shell for users created with SSSD userspace tools."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2521
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <filename>/bin/bash</filename>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: <filename>bash/bin/bash</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2526
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "base_directory (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "base_directory (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2529
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The tools append the login name to <replaceable>base_directory</replaceable> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"and use that as the home directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2534
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <filename>/home</filename>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: <filename>/ home</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2539
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "create_homedir (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "create_homedir (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2542
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Indicate if a home directory should be created by default for new users. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Can be overridden on command line."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2546 sssd.conf.5.xml:2558
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: TRUE"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: TRUE"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2551
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "remove_homedir (bool)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "remove_homedir (bool)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2554
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Indicate if a home directory should be removed by default for deleted "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"users. Can be overridden on command line."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2563
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "homedir_umask (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "homedir_umask (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2566
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Used by <citerefentry> <refentrytitle>sss_useradd</refentrytitle> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<manvolnum>8</manvolnum> </citerefentry> to specify the default permissions "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"on a newly created home directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2574
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 077"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 077"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2579
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "skel_dir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "skel_dir (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2582
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The skeleton directory, which contains files and directories to be copied in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the user's home directory, when the home directory is created by "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sss_useradd</refentrytitle> <manvolnum>8</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2592
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <filename>/etc/skel</filename>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: <filename>skel/etc/skel</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2597
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "mail_dir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "mail_dir (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2600
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The mail spool directory. This is needed to manipulate the mailbox when its "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"corresponding user account is modified or deleted. If not specified, a "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"default value is used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2607
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <filename>/var/mail</filename>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: <filename>mail/var/mail</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2612
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "userdel_cmd (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "userdel_cmd (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2615
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The command that is run after a user is removed. The command us passed the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"username of the user being removed as the first and only parameter. The "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"return code of the command is not taken into account."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2621
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: None, no command is run"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: None, nenhum comando é executado"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2631 sssd-ldap.5.xml:2662 sssd-simple.5.xml:131
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:717 sssd-ad.5.xml:992 sssd-krb5.5.xml:570
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:98
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "EXAMPLE"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "EXEMPLO"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2637
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#, no-wrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"[sssd]\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"domains = LDAP\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"services = nss, pam\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"config_file_version = 2\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"[nss]\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"filter_groups = root\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"filter_users = root\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"[pam]\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"[domain/LDAP]\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"id_provider = ldap\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"ldap_uri = ldap://ldap.example.com\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"ldap_search_base = dc=example,dc=com\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"auth_provider = krb5\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"krb5_server = kerberos.example.com\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"krb5_realm = EXAMPLE.COM\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"cache_credentials = true\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"min_id = 10000\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"max_id = 20000\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"enumerate = False\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"[sssd]\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"domains = LDAP\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"services = nss, pam\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"config_file_version = 2\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"[nss]\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"filter_groups = root\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"filter_users = root\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"[pam]\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"[domain/LDAP]\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"id_provider = ldap\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"ldap_uri = ldap://ldap.example.com\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"ldap_search_base = dc=example,dc=com\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"auth_provider = krb5\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"krb5_server = kerberos.example.com\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"krb5_realm = EXAMPLE.COM\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"cache_credentials = true\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"min_id = 10000\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"max_id = 20000\n"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"enumerate = False\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.conf.5.xml:2633
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following example shows a typical SSSD config. It does not describe "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"configuration of the domains themselves - refer to documentation on "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"configuring domains for more details. <placeholder type=\"programlisting\" "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:10 sssd-ldap.5.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd-ldap"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sssd-ldap"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD LDAP provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:23
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This manual page describes the configuration of LDAP domains for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"</citerefentry>. Refer to the <quote>FILE FORMAT</quote> section of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> manual page for detailed syntax information."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:35
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "You can configure SSSD to use more than one LDAP domain."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:38
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP back end supports id, auth, access and chpass providers. If you want to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authenticate against an LDAP server either TLS/SSL or LDAPS is required. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sssd</command> <emphasis>does not</emphasis> support authentication "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"over an unencrypted channel. If the LDAP server is used only as an identity "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"provider, an encrypted channel is not needed. Please refer to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>ldap_access_filter</quote> config option for more information about "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"using LDAP as an access provider."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ldap.5.xml:49 sssd-simple.5.xml:69 sssd-ipa.5.xml:70 sssd-ad.5.xml:89
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-krb5.5.xml:63 sssd-ifp.5.xml:44 sssd-secrets.5.xml:94
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "CONFIGURATION OPTIONS"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "OPÇÕES DE CONFIGURAÇÃO"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:60
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ldap_uri, ldap_backup_uri (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:63
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"should connect in the order of preference. Refer to the <quote>FAILOVER</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"quote> section for more information on failover and server redundancy. If "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"neither option is specified, service discovery is enabled. For more "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"information, refer to the <quote>SERVICE DISCOVERY</quote> section."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:70 sssd-secrets.5.xml:185
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The format of the URI must match the format defined in RFC 2732:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:73
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap[s]://&lt;host&gt;[:port]"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap[s]://&lt;host&gt;[:port]"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:76
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For explicit IPv6 addresses, &lt;host&gt; must be enclosed in brackets []"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:79
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "example: ldap://[fc00::126:25]:389"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:85
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ldap_chpass_uri, ldap_chpass_backup_uri (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:88
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the comma-separated list of URIs of the LDAP servers to which SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"should connect in the order of preference to change the password of a user. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Refer to the <quote>FAILOVER</quote> section for more information on "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"failover and server redundancy."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:95
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "To enable service discovery ldap_chpass_dns_service_name must be set."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:99
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: empty, i.e. ldap_uri is used."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: empty, ou seja, ldap_uri é usado."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:105
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_search_base (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_search_base (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:108
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The default base DN to use for performing LDAP user operations."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ldap.5.xml:112
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Starting with SSSD 1.7.0, SSSD supports multiple search bases using the "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"syntax:"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:116
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "search_base[?scope?[filter][?search_base?scope?[filter]]*]"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:119
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "The scope can be one of \"base\", \"onelevel\" or \"subtree\"."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ldap.5.xml:122 include/ldap_search_bases.xml:18
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"The filter must be a valid LDAP search filter as specified by http://www."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ietf.org/rfc/rfc2254.txt"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:126 sssd-ldap.5.xml:662 sssd-ad.5.xml:247
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:137 sss_override.8.xml:234
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "Examples:"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Exemplos:"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:129
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = dc=example,dc=com (which is equivalent to) "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = dc=example,dc=com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"ldap_search_base = dc=example,dc=com (which is equivalent to) "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"ldap_search_base = dc=example,dc=com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:134
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"(host=thishost)?dc=example.com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"ldap_search_base = cn=host_specific,dc=example,dc=com?subtree?"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"(host=thishost)?dc=example.com?subtree?"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:137
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Note: It is unsupported to have multiple search bases which reference "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"identically-named objects (for example, groups with the same name in two "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"different search bases). This will lead to unpredictable behavior on client "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"machines."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:144
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"Default: If not set, the value of the defaultNamingContext or namingContexts "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"attribute from the RootDSE of the LDAP server is used. If "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"defaultNamingContext does not exist or has an empty value namingContexts is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"used. The namingContexts attribute must have a single value with the DN of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the search base of the LDAP server to make this work. Multiple values are "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are not supported."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:158
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_schema (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#: sssd-ldap.5.xml:161
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the Schema Type in use on the target LDAP server. Depending on "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the selected schema, the default attribute names retrieved from the servers "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"may vary. The way that some attributes are handled may also differ."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:168
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Four schema types are currently supported:"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:172
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "rfc2307"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:177
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "rfc2307bis"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:182
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "IPA"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:187
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "AD"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:193
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"The main difference between these schema types is how group memberships are "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"recorded in the server. With rfc2307, group members are listed by name in "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"the <emphasis>memberUid</emphasis> attribute. With rfc2307bis and IPA, "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"group members are listed by DN and stored in the <emphasis>member</emphasis> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"attribute. The AD schema type sets the attributes to correspond with Active "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Directory 2008r2 values."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:203
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: rfc2307"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:209
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_default_bind_dn (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:212
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The default bind DN to use for performing LDAP operations."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:219
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_default_authtok_type (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:222
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The type of the authentication token of the default bind DN."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:226
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The two mechanisms currently supported are:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:229
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "password"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:232
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "obfuscated_password"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:235
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: password"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:241
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_default_authtok (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:244
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The authentication token of the default bind DN. Only clear text passwords "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are currently supported."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:251
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_object_class (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:254
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The object class of a user entry in LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:257
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: posixAccount"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:263
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:266
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's login name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sssd-ldap.5.xml:270
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: uid (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:277
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_uid_number (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:280
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's id."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:284
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: uidNumber"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:290
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_gid_number (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:293
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's primary group id."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:297 sssd-ldap.5.xml:893
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: gidNumber"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:303
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "ldap_user_principal (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "ldap_user_primary_group (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "ldap_user_principal (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:306
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Active Directory primary group attribute for ID-mapping. Note that this "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"attribute should only be set manually if you are running the <quote>ldap</"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"quote> provider with ID mapping."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:312
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: unset (LDAP), primaryGroupID (AD)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:318
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_gecos (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:321
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's gecos field."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:325
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: gecos"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:331
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_home_directory (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:334
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that contains the name of the user's home directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:338
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: homeDirectory"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: homeDirectory"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:344
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shell (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shell (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:347
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that contains the path to the user's default shell."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:351
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: loginShell"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: diret"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:357
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_user_uuid (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:360
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The LDAP attribute that contains the UUID/GUID of an LDAP user object."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:364 sssd-ldap.5.xml:919
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Default: not set in the general case, objectGUID for AD and ipaUniqueID for "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"IPA"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:371
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_user_objectsid (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:374
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The LDAP attribute that contains the objectSID of an LDAP user object. This "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"is usually only necessary for ActiveDirectory servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:379 sssd-ldap.5.xml:934
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: objectSid for ActiveDirectory, not set for other servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:386
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_modify_timestamp (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_modify_timestamp (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:389 sssd-ldap.5.xml:944 sssd-ldap.5.xml:1167
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The LDAP attribute that contains timestamp of the last modification of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"parent object."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:393 sssd-ldap.5.xml:948 sssd-ldap.5.xml:1174
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: modifyTimestamp"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: modifyTimestamp"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:399
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_last_change (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_last_change (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:402
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (date of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the last password change)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:412
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowLastChange"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowLastChange"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:418
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_min (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_min (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:421
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (minimum "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"password age)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:430
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowMin"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowMin"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:436
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_max (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_max (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:439
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart (maximum "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"password age)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:448
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowMax"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowMax"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:454
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_warning (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_warning (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:457
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(password warning period)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:467
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowWarning"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowWarning"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:473
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_inactive (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_inactive (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:476
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow, this parameter contains the name of an "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP attribute corresponding to its <citerefentry> <refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> counterpart "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(password inactivity period)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:486
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowInactive"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowInactive"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:492
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_shadow_expire (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_shadow_expire (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:495
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=shadow or ldap_account_expire_policy=shadow, this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"parameter contains the name of an LDAP attribute corresponding to its "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>shadow</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> counterpart (account expiration date)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:505
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: shadowExpire"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: shadowExpire"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:511
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_krb_last_pwd_change (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_krb_last_pwd_change (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:514
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"an LDAP attribute storing the date and time of last password change in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"kerberos."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:520
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: krbLastPwdChange"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: krbLastPwdChange"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:526
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_krb_password_expiration (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_krb_password_expiration (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:529
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_pwd_policy=mit_kerberos, this parameter contains the name of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"an LDAP attribute storing the date and time when current password expires."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:535
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: krbPasswordExpiration"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: krbPasswordExpiration"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:541
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_ad_account_expires (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:544
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"of an LDAP attribute storing the expiration time of the account."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:549
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: accountExpires"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:555
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_ad_user_account_control (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:558
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=ad, this parameter contains the name "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"of an LDAP attribute storing the user account control bit field."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:563
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: userAccountControl"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:569
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_ns_account_lock (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:572
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=rhds or equivalent, this parameter "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"determines if access is allowed or not."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:577
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: nsAccountLock"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:583
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_nds_login_disabled (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:586
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"access is allowed or not."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:590 sssd-ldap.5.xml:604
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: loginDisabled"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:596
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_nds_login_expiration_time (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:599
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines until "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"which date access is granted."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:610
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_nds_login_allowed_time_map (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:613
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using ldap_account_expire_policy=nds, this attribute determines the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"hours of a day in a week when access is granted."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:618
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: loginAllowedTimeMap"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:624
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_principal (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_principal (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:627
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The LDAP attribute that contains the user's Kerberos User Principal Name "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"(UPN)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:631
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: krbPrincipalName"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: krbPrincipalName"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:637
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:640
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Comma-separated list of LDAP attributes that SSSD would fetch along with the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"usual set of user attributes."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:645
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The list can either contain LDAP attribute names only, or colon-separated "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"tuples of SSSD cache attribute name and LDAP attribute name. In case only "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"LDAP attribute name is specified, the attribute is saved to the cache "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"verbatim. Using a custom SSSD attribute name might be required by "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"environments that configure several SSSD domains with different LDAP schemas."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:655
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that several attribute names are reserved by SSSD, notably the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>name</quote> attribute. SSSD would report an error if any of the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"reserved attribute names is used as an extra attribute name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:665
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs = telephoneNumber"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:668
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Save the <quote>telephoneNumber</quote> attribute from LDAP as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote>telephoneNumber</quote> to the cache."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:672
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_extra_attrs = phone:telephoneNumber"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:675
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Save the <quote>telephoneNumber</quote> attribute from LDAP as <quote>phone</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> to the cache."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:685
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_user_ssh_public_key (string)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:688
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The LDAP attribute that contains the user's SSH public keys."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:692
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: sshPublicKey"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:698
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_force_upper_case_realm (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap_force_upper_case_realm (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:701
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Some directory servers, for example Active Directory, might deliver the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"realm part of the UPN in lower case, which might cause the authentication to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fail. Set this option to a non-zero value if you want to use an upper-case "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"realm."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:714
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_enumeration_refresh_timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr "ldap_enumeration_refresh_timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:717
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Specifies how many seconds SSSD has to wait before refreshing its cache of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"enumerated records."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:728
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_purge_cache_timeout (integer)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:731
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Determine how often to check the cache for inactive entries (such as groups "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"with no members and users who have never logged in) and remove them to save "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"space."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:737
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Setting this option to zero will disable the cache cleanup operation. Please "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"note that if enumeration is enabled, the cleanup task is required in order "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"to detect entries removed from the server and can't be disabled. By default, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the cleanup task will run every 3 hours with enumeration enabled."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:752
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_fullname (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_fullname (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:755
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the user's full name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:759 sssd-ldap.5.xml:1125 sssd-ldap.5.xml:1199
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2240 sssd-ipa.5.xml:590
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: cn"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: NC"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:765
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_member_of (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:768
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that lists the user's group memberships."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:772
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: memberOf"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:778
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_authorized_service (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:781
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If access_provider=ldap and ldap_access_order=authorized_service, SSSD will "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"use the presence of the authorizedService attribute in the user's LDAP entry "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to determine access privilege."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:788
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"An explicit deny (!svc) is resolved first. Second, SSSD searches for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"explicit allow (svc) and finally for allow_all (*)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:793
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>authorized_service</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_user_authorized_service option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:800
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: authorizedService"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:806
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_authorized_host (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_authorized_host (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:809
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If access_provider=ldap and ldap_access_order=host, SSSD will use the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"presence of the host attribute in the user's LDAP entry to determine access "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"privilege."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:815
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"An explicit deny (!host) is resolved first. Second, SSSD searches for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"explicit allow (host) and finally for allow_all (*)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:820
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>host</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_user_authorized_host option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:827
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: host"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: host"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:833
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ldap_user_certificate (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:836
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Name of the LDAP attribute containing the X509 certificate of the user."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:840
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: no set in the general case, userCertificate;binary for IPA"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:847
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#, fuzzy
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#| msgid "ldap_user_shell (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "ldap_user_email (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr "ldap_user_shell (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:850
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "Name of the LDAP attribute containing the email address of the user."
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:854
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#, fuzzy
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#| msgid "Default: false"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "Default: mail"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr "Padrão: false"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:860
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_object_class (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:863
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The object class of a group entry in LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:866
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: posixGroup"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:872
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:875
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the group name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:879
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: cn (rfc2307, rfc2307bis and IPA), sAMAccountName (AD)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:886
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_gid_number (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:889
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the group's id."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:899
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_member (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:902
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that contains the names of the group's members."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:906
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: memberuid (rfc2307) / member (rfc2307bis)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:912
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_group_uuid (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:915
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "The LDAP attribute that contains the UUID/GUID of an LDAP group object."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:926
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_group_objectsid (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:929
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The LDAP attribute that contains the objectSID of an LDAP group object. This "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"is usually only necessary for ActiveDirectory servers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:941
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_modify_timestamp (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:954
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_group_type (integer)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:957
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The LDAP attribute that contains an integer value indicating the type of the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"group and maybe other flags."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:962
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This attribute is currently only used by the AD provider to determine if a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"group is a domain local groups and has to be filtered out for trusted "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domains."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:968
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: groupType in the AD provider, othewise not set"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:975
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "ldap_group_search_base (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_group_external_member (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_group_search_base (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:978
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The LDAP attribute that references group members that are defined in an "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"external domain. At the moment, only IPA's external members are supported."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:984
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: ipaExternalMember in the IPA provider, otherwise unset."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:991
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_nesting_level (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:994
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If ldap_schema is set to a schema format that supports nested groups (e.g. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"RFC2307bis), then this option controls how many levels of nesting SSSD will "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"follow. This option has no effect on the RFC2307 schema."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1001
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Note: This option specifies the guaranteed level of nested groups to be "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"processed for any lookup. However, nested groups beyond this limit "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<emphasis>may be</emphasis> returned if previous lookups already resolved "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the deeper nesting levels. Also, subsequent lookups for other groups may "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"enlarge the result set for original lookup if re-queried."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1010
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"If ldap_group_nesting_level is set to 0 then no nested groups are processed "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"at all. However, when connected to Active-Directory Server 2008 and later "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"using <quote>id_provider=ad</quote> it is furthermore required to disable "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"usage of Token-Groups by setting ldap_use_tokengroups to false in order to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"restrict group nesting."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1019
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 2"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1025
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_groups_use_matching_rule_in_chain"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1028
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option tells SSSD to take advantage of an Active Directory-specific "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"feature which may speed up group lookup operations on deployments with "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"complex or deep nested groups."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1034
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"In most common cases, it is best to leave this option disabled. It generally "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"only provides a performance increase on very complex nestings."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1039 sssd-ldap.5.xml:1066
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"If this option is enabled, SSSD will use it if it detects that the server "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"supports it during initial connection. So \"True\" here essentially means "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"\"auto-detect\"."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1045 sssd-ldap.5.xml:1072
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"Note: This feature is currently known to work only with Active Directory "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"2008 R1 and later. See <ulink url=\"http://msdn.microsoft.com/en-us/library/"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"windows/desktop/aa746475%28v=vs.85%29.aspx\"> MSDN(TM) documentation</ulink> "
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"for more details."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1057
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_initgroups_use_matching_rule_in_chain"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1060
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"This option tells SSSD to take advantage of an Active Directory-specific "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"feature which might speed up initgroups operations (most notably when "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"dealing with complex or deep nested groups)."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1087
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"This options enables or disables use of Token-Groups attribute when "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"performing initgroup for users from Active Directory Server 2008 and later."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1092
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: True for AD and IPA otherwise False."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1098
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ldap_netgroup_object_class (string)"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1101
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The object class of a netgroup entry in LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1104
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_object_class should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1108
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: nisNetgroup"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1114
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_netgroup_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1117
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that corresponds to the netgroup name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1121
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_name should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1131
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_netgroup_member (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1134
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The LDAP attribute that contains the names of the netgroup's members."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1138
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "In IPA provider, ipa_netgroup_member should be used instead."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1142
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: memberNisNetgroup"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1148
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_netgroup_triple (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1151
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The LDAP attribute that contains the (host, user, domain) netgroup triples."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1155 sssd-ldap.5.xml:1171
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "This option is not available in IPA provider."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1158
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: nisNetgroupTriple"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: nisNetgroupTriple"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1164
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_netgroup_modify_timestamp (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_netgroup_modify_timestamp (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1180
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_object_class (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1183
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a service entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1186
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipService"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1192
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_name (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1195
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the name of service attributes and their "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"aliases."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1205
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_port (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1208
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that contains the port managed by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1212
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipServicePort"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1218
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_proto (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1221
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that contains the protocols understood by this service."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1225
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: ipServiceProtocol"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1231
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_service_search_base (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1236
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_search_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_search_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1239
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the timeout (in seconds) that ldap searches are allowed to run "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"before they are cancelled and cached results are returned (and offline mode "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"is entered)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1245
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Note: this option is subject to change in future versions of the SSSD. It "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"will likely be replaced at some point by a series of timeouts for specific "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"lookup types."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1257
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_enumeration_search_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1260
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the timeout (in seconds) that ldap searches for user and group "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"enumerations are allowed to run before they are cancelled and cached results "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are returned (and offline mode is entered)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1273
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_network_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_network_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1276
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the timeout (in seconds) after which the <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>poll</refentrytitle> <manvolnum>2</manvolnum> </citerefentry>/"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>select</refentrytitle> <manvolnum>2</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> following a <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>connect</refentrytitle> <manvolnum>2</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> returns in case of no activity."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1299
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_opt_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_opt_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1302
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies a timeout (in seconds) after which calls to synchronous LDAP APIs "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"will abort if no response is received. Also controls the timeout when "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"communicating with the KDC in case of SASL bind, the timeout of an LDAP bind "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"operation, password change extended operation and the StartTLS operation."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1317
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "ldap_connection_expire_timeout (integer)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1320
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies a timeout (in seconds) that a connection to an LDAP server will be "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"maintained. After this time, the connection will be re-established. If used "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"in parallel with SASL/GSSAPI, the sooner of the two values (this value vs. "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"the TGT lifetime) will be used."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1328 sssd-ldap.5.xml:2397
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Default: 900 (15 minutes)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1334
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_page_size (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_page_size (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1337
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specify the number of records to retrieve from LDAP in a single request. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Some LDAP servers enforce a maximum limit per-request."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1342
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 1000"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 1000"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1348
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_disable_paging (boolean)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1351
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Disable the LDAP paging control. This option should be used if the LDAP "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"server reports that it supports the LDAP paging control in its RootDSE but "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"it is not enabled or does not behave properly."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1357
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Example: OpenLDAP servers with the paging control module installed on the "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"server but not enabled will report it in the RootDSE but be unable to use it."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1363
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Example: 389 DS has a bug where it can only support a one paging control at "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"a time on a single connection. On busy clients, this can result in some "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"requests being denied."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1375
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "ldap_disable_range_retrieval (boolean)"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1378
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "Disable Active Directory range retrieval."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1381
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Active Directory limits the number of members to be retrieved in a single "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"lookup using the MaxValRange policy (which defaults to 1500 members). If a "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"group contains more members, the reply would include an AD-specific range "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"extension. This option disables parsing of the range extension, therefore "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"large groups will appear as having no members."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1396
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_sasl_minssf (integer)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1399
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When communicating with an LDAP server using SASL, specify the minimum "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"security level necessary to establish the connection. The values of this "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"option are defined by OpenLDAP."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1405
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: Use the system default (usually specified by ldap.conf)"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1412
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_deref_threshold (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1415
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specify the number of group members that must be missing from the internal "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"cache in order to trigger a dereference lookup. If less members are missing, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"they are looked up individually."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1421
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"You can turn off dereference lookups completely by setting the value to 0."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1425
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"A dereference lookup is a means of fetching all group members in a single "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"LDAP call. Different LDAP servers may implement different dereference "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"methods. The currently supported servers are 389/RHDS, OpenLDAP and Active "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1433
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"<emphasis>Note:</emphasis> If any of the search bases specifies a search "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"filter, then the dereference lookup performance enhancement will be disabled "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"regardless of this setting."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1446
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_reqcert (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_tls_reqcert (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1449
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies what checks to perform on server certificates in a TLS session, if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"any. It can be specified as one of the following values:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1455
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>never</emphasis> = The client will not request or check any server "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"certificate."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<emphasis>never</emphasis> = O cliente não irá solicitar ou verificar "
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"qualquer certificado de servidor."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1459
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>allow</emphasis> = The server certificate is requested. If no "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"certificate is provided, the session proceeds normally. If a bad certificate "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"is provided, it will be ignored and the session proceeds normally."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1466
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>try</emphasis> = The server certificate is requested. If no "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"certificate is provided, the session proceeds normally. If a bad certificate "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"is provided, the session is immediately terminated."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1472
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>demand</emphasis> = The server certificate is requested. If no "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"certificate is provided, or a bad certificate is provided, the session is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"immediately terminated."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1478
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>hard</emphasis> = Same as <quote>demand</quote>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1482
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: hard"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: hard"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1488
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_cacert (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_tls_cacert (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1491
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the file that contains certificates for all of the Certificate "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Authorities that <command>sssd</command> will recognize."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1496 sssd-ldap.5.xml:1514 sssd-ldap.5.xml:1555
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: use OpenLDAP defaults, typically in <filename>/etc/openldap/ldap."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"conf</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1503
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_cacertdir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_tls_cacertdir (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1506
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the path of a directory that contains Certificate Authority "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"certificates in separate individual files. Typically the file names need to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"be the hash of the certificate followed by '.0'. If available, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>cacertdir_rehash</command> can be used to create the correct names."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1521
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_cert (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1524
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies the file that contains the certificate for the client's key."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1534
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_key (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1537
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies the file that contains the client's key."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1546
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_tls_cipher_suite (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1549
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Specifies acceptable cipher suites. Typically this is a colon separated "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"list. See <citerefentry><refentrytitle>ldap.conf</refentrytitle> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<manvolnum>5</manvolnum></citerefentry> for format."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1562
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_id_use_start_tls (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_id_use_start_tls (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1565
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies that the id_provider connection must also use <systemitem class="
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"\"protocol\">tls</systemitem> to protect the channel."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1575
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_id_mapping (boolean)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1578
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies that SSSD should attempt to map user and group IDs from the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_user_objectsid and ldap_group_objectsid attributes instead of relying "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"on ldap_user_uid_number and ldap_group_gid_number."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1584
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Currently this feature supports only ActiveDirectory objectSID mapping."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1594
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "ldap_min_id, ldap_max_id (interger)"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1597
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"In contrast to the SID based ID mapping which is used if ldap_id_mapping is "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"set to true the allowed ID range for ldap_user_uid_number and "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"ldap_group_gid_number is unbound. In a setup with sub/trusted-domains this "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"might lead to ID collisions. To avoid collisions ldap_min_id and ldap_max_id "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"can be set to restrict the allowed range for the IDs which are read directly "
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek"from the server. Sub-domains can then pick other ranges to map IDs."
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1609
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid "Default: not set (both options are set to 0)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1615
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_sasl_mech (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_sasl_mech (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1618
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specify the SASL mechanism to use. Currently only GSSAPI is tested and "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"supported."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1628
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_sasl_authid (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_sasl_authid (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1631
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specify the SASL authorization id to use. When GSSAPI is used, this "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"represents the Kerberos principal used for authentication to the directory. "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"This option can either contain the full principal (for example host/"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"myhost@EXAMPLE.COM) or just the principal name (for example host/myhost)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1639
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: host/hostname@REALM"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1645
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_sasl_realm (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1648
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Specify the SASL realm to use. When not specified, this option defaults to "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"the value of krb5_realm. If the ldap_sasl_authid contains the realm as "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"well, this option is ignored."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1654
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: the value of krb5_realm."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1660
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_sasl_canonicalize (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_sasl_canonicalize (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1663
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If set to true, the LDAP library would perform a reverse lookup to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"canonicalize the host name during a SASL bind."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1668
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: false;"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: false;"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1674
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_krb5_keytab (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_krb5_keytab (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1677
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specify the keytab to use when using SASL/GSSAPI."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1680
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: System keytab, normally <filename>/etc/krb5.keytab</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Padrão: Sistema keytab, normalmente <filename>/etc/krb5.keytab</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1686
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_krb5_init_creds (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_krb5_init_creds (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1689
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies that the id_provider should init Kerberos credentials (TGT). This "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"action is performed only if SASL is used and the mechanism selected is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"GSSAPI."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1701
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_krb5_ticket_lifetime (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_krb5_ticket_lifetime (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1704
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies the lifetime in seconds of the TGT if GSSAPI is used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1708 sssd-ad.5.xml:886
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: 86400 (24 hours)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: 86400 (24 horas)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1714 sssd-krb5.5.xml:74
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "krb5_server, krb5_backup_server (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1717
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the comma-separated list of IP addresses or hostnames of the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Kerberos servers to which SSSD should connect in the order of preference. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For more information on failover and server redundancy, see the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>FAILOVER</quote> section. An optional port number (preceded by a "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"colon) may be appended to the addresses or hostnames. If empty, service "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"discovery is enabled - for more information, refer to the <quote>SERVICE "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"DISCOVERY</quote> section."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1729 sssd-krb5.5.xml:89
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When using service discovery for KDC or kpasswd servers, SSSD first searches "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"for DNS entries that specify _udp as the protocol and falls back to _tcp if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"none are found."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1734 sssd-krb5.5.xml:94
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This option was named <quote>krb5_kdcip</quote> in earlier releases of SSSD. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"While the legacy name is recognized for the time being, users are advised to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"migrate their config files to use <quote>krb5_server</quote> instead."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1743 sssd-ipa.5.xml:415 sssd-krb5.5.xml:103
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_realm (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_realm (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1746
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specify the Kerberos REALM (for SASL/GSSAPI auth)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1749
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: System defaults, see <filename>/etc/krb5.conf</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1755 sssd-ipa.5.xml:430 sssd-krb5.5.xml:462
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid "krb5_canonicalize (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_canonicalize (boolean)"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1758
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host principal should be canonicalized when connecting to "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"LDAP server. This feature is available with MIT Kerberos >= 1.7"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1770 sssd-krb5.5.xml:477
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid "krb5_use_kdcinfo (boolean)"
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1773 sssd-krb5.5.xml:480
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"Specifies if the SSSD should instruct the Kerberos libraries what realm and "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"which KDCs to use. This option is on by default, if you disable it, you need "
0172959f117b545c8a6b1893f5f56818d82dd624Jakub Hrozek"to configure the Kerberos library using the <citerefentry> "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"<refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</manvolnum> </"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"citerefentry> configuration file."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1784 sssd-krb5.5.xml:491
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"See the <citerefentry> <refentrytitle>sssd_krb5_locator_plugin</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> manual page for more "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"information on the locator plugin."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1798
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_pwd_policy (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_pwd_policy (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1801
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Select the policy to evaluate the password expiration on the client side. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following values are allowed:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1806
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>none</emphasis> - No evaluation on the client side. This option "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"cannot disable server-side password policies."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1811
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>shadow</emphasis> - Use <citerefentry><refentrytitle>shadow</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum></citerefentry> style attributes to "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"evaluate if the password has expired."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1817
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>mit_kerberos</emphasis> - Use the attributes used by MIT Kerberos "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to determine if the password has expired. Use chpass_provider=krb5 to update "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"these attributes when the password is changed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1826
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: if a password policy is configured on server "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"side, it always takes precedence over policy set with this option."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1834
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_referrals (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1837
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies whether automatic referral chasing should be enabled."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1841
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that sssd only supports referral chasing when it is compiled "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"with OpenLDAP version 2.4.13 or higher."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1846
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Chasing referrals may incur a performance penalty in environments that use "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"them heavily, a notable example is Microsoft Active Directory. If your setup "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"does not in fact require the use of referrals, setting this option to false "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"might bring a noticeable performance improvement."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1860
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_dns_service_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1863
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies the service name to use when service discovery is enabled."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1867
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: ldap"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1873
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_chpass_dns_service_name (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1876
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the service name to use to find an LDAP server which allows "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"password changes when service discovery is enabled."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1881
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: not set, i.e. service discovery is disabled"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1887
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "ldap_chpass_update_last_change (bool)"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1890
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Specifies whether to update the ldap_user_shadow_last_change attribute with "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"days since the Epoch after a password change operation."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1902
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_access_filter (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1905
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"If using access_provider = ldap and ldap_access_order = filter (default), "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"this option is mandatory. It specifies an LDAP search filter criteria that "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"must be met for the user to be granted access on this host. If "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"access_provider = ldap, ldap_access_order = filter and this option is not "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"set, it will result in all users being denied access. Use access_provider = "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permit to change this default behavior. Please note that this filter is "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"applied on the LDAP user entry only and thus filtering based on nested "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"groups may not work (e.g. memberOf attribute on AD entries points only to "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"direct parents). If filtering based on nested groups is required, please see "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<citerefentry> <refentrytitle>sssd-simple</refentrytitle><manvolnum>5</"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manvolnum> </citerefentry>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1925
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Example:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1928
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#, no-wrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"access_provider = ldap\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"ldap_access_filter = (employeeType=admin)\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher" "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1932
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This example means that access to this host is restricted to users whose "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"employeeType attribute is set to \"admin\"."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1937
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Offline caching for this feature is limited to determining whether the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"user's last online login was granted access permission. If they were granted "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"access during their last login, they will continue to be granted access "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"while offline and vice-versa."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1945 sssd-ldap.5.xml:2002
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: Empty"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1951
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_account_expire_policy (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1954
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"With this option a client side evaluation of access control attributes can "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"be enabled."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1958
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that it is always recommended to use server side access control, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"i.e. the LDAP server should deny the bind request with a suitable error code "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"even if the password is correct."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1965
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The following values are allowed:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1968
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>shadow</emphasis>: use the value of ldap_user_shadow_expire to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"determine if the account is expired."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1973
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>ad</emphasis>: use the value of the 32bit field "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_ad_user_account_control and allow access if the second bit is not "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"set. If the attribute is missing access is granted. Also the expiration time "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"of the account is checked."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1980
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>rhds</emphasis>, <emphasis>ipa</emphasis>, <emphasis>389ds</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"emphasis>: use the value of ldap_ns_account_lock to check if access is "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"allowed or not."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1986
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>nds</emphasis>: the values of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_nds_login_allowed_time_map, ldap_user_nds_login_disabled and "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"ldap_user_nds_login_expiration_time are used to check if access is allowed. "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"If both attributes are missing access is granted."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:1995
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Please note that the ldap_access_order configuration option <emphasis>must</"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"emphasis> include <quote>expire</quote> in order for the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"ldap_account_expire_policy option to work."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2008
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_access_order (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2011
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Comma separated list of access control options. Allowed values are:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2015
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>filter</emphasis>: use ldap_access_filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2018
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<emphasis>lockout</emphasis>: use account locking. If set, this option "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"and has value of '000001010000Z'. Please see the option ldap_pwdlockout_dn. "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Please note that 'access_provider = ldap' must be set for this feature to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"work."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2028
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis> Please note that this option is superseded by the <quote>ppolicy</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"quote> option and might be removed in a future release. </emphasis>"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2035
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis>ppolicy</emphasis>: use account locking. If set, this option "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"denies access in case that ldap attribute 'pwdAccountLockedTime' is present "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"and has value of '000001010000Z' or represents any time in the past. The "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"value of the 'pwdAccountLockedTime' attribute must end with 'Z', which "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"denotes the UTC time zone. Other time zones are not currently supported and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"will result in \"access-denied\" when users attempt to log in. Please see "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"the option ldap_pwdlockout_dn. Please note that 'access_provider = ldap' "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"must be set for this feature to work."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2052
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>expire</emphasis>: use ldap_account_expire_policy"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2056
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<emphasis>pwd_expire_policy_reject, pwd_expire_policy_warn, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_renew: </emphasis> These options are useful if users are "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"interested in being warned that password is about to expire and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"authentication is based on using a different method than passwords - for "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"example SSH keys."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2066
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The difference between these options is the action taken if user password is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"expired: pwd_expire_policy_reject - user is denied to log in, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_warn - user is still able to log in, "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"pwd_expire_policy_renew - user is prompted to change his password "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"immediately."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2074
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note If user password is expired no explicit message is prompted by SSSD."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2078
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Please note that 'access_provider = ldap' must be set for this feature to "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"work. Also 'ldap_pwd_policy' must be set to an appropriate password policy."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2083
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>authorized_service</emphasis>: use the authorizedService attribute "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"to determine access"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2088
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>host</emphasis>: use the host attribute to determine access"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2092
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "Padrão: filter"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2095
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Please note that it is a configuration error if a value is used more than "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"once."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2102
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ldap_pwdlockout_dn (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2105
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This option specifies the DN of password policy entry on LDAP server. Please "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"note that absence of this option in sssd.conf in case of enabled account "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"lockout checking will yield access denied as ppolicy attributes on LDAP "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"server cannot be checked properly."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2113
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Example: cn=ppolicy,ou=policies,dc=example,dc=com"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2116
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: cn=ppolicy,ou=policies,$ldap_search_base"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2122
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_deref (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr "ldap_deref (string)"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2125
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Specifies how alias dereferencing is done when performing a search. The "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"following options are allowed:"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2130
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "<emphasis>never</emphasis>: Aliases are never dereferenced."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2134
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>searching</emphasis>: Aliases are dereferenced in subordinates of "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the base object, but not in locating the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2139
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>finding</emphasis>: Aliases are only dereferenced when locating "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2144
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<emphasis>always</emphasis>: Aliases are dereferenced both in searching and "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"in locating the base object of the search."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2149
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"Default: Empty (this is handled as <emphasis>never</emphasis> by the LDAP "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"client libraries)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2157
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "ldap_rfc2307_fallback_to_local_users (boolean)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2160
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Allows to retain local users as members of an LDAP group for servers that "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"use the RFC2307 schema."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2164
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"In some environments where the RFC2307 schema is used, local users are made "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"members of LDAP groups by adding their names to the memberUid attribute. "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The self-consistency of the domain is compromised when this is done, so SSSD "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"would normally remove the \"missing\" users from the cached group "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"memberships as soon as nsswitch tries to fetch information about the user "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"via getpw*() or initgroups() calls."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2175
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"This option falls back to checking if local users are referenced, and caches "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"them so that later initgroups() calls will augment the local users with the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"additional LDAP groups."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2187 sssd-ifp.5.xml:136
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "ldap_opt_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "wildcart_limit (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "ldap_opt_timeout (integer)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2190
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies an upper limit on the number of entries that are downloaded during "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"a wildcard lookup."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2194
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "At the moment, only the InfoPipe responder supports wildcard lookups."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2198
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: 1000 (often the size of one page)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#: sssd-ldap.5.xml:51
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"All of the common configuration options that apply to SSSD domains also "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"apply to LDAP domains. Refer to the <quote>DOMAIN SECTIONS</quote> section "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"of the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"manvolnum> </citerefentry> manual page for full details. <placeholder type="
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"\"variablelist\" id=\"0\"/>"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2208
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "SUDO OPTIONS"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2210
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The detailed instructions for configuration of sudo_provider are in the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"manual page <citerefentry> <refentrytitle>sssd-sudo</refentrytitle> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2221
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_object_class (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2224
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of a sudo rule entry in LDAP."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2227
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRole"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2233
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_name (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2236
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo rule name."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2246
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_command (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2249
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the command name."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2253
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoCommand"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2259
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_host (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2262
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the host name (or host IP address, "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"host IP network, or host netgroup)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2267
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoHost"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2273
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_user (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2276
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the user name (or UID, group name or "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"user's netgroup)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2280
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoUser"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2286
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_option (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2289
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the sudo options."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2293
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoOption"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2299
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_runasuser (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2302
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the user name that commands may be "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"run as."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2306
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRunAsUser"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2312
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_runasgroup (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2315
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the group name or group GID that "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"commands may be run as."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2319
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoRunAsGroup"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2325
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_notbefore (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2328
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the start date/time for when the sudo "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"rule is valid."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2332
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoNotBefore"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2338
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_notafter (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2341
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The LDAP attribute that corresponds to the expiration date/time, after which "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the sudo rule will no longer be valid."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2346
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoNotAfter"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2352
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudorule_order (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2355
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The LDAP attribute that corresponds to the ordering index of the rule."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2359
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Default: sudoOrder"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2365
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_full_refresh_interval (integer)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2368
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds SSSD will wait between executing a full refresh of sudo "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"rules (which downloads all rules that are stored on the server)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2373
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The value must be greater than <emphasis>ldap_sudo_smart_refresh_interval </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"emphasis>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2378
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: 21600 (6 hours)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2384
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_smart_refresh_interval (integer)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2387
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"How many seconds SSSD has to wait before executing a smart refresh of sudo "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"rules (which downloads all rules that have USN higher than the highest USN "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"of cached rules)."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2393
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If USN attributes are not supported by the server, the modifyTimestamp "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"attribute is used instead."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2403
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_use_host_filter (boolean)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2406
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If true, SSSD will download only rules that are applicable to this machine "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"(using the IPv4 or IPv6 host/network addresses and hostnames)."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2417
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_hostnames (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2420
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Space separated list of hostnames or fully qualified domain names that "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"should be used to filter the rules."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2425
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"If this option is empty, SSSD will try to discover the hostname and the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"fully qualified domain name automatically."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2430 sssd-ldap.5.xml:2453 sssd-ldap.5.xml:2471
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2489
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If <emphasis>ldap_sudo_use_host_filter</emphasis> is <emphasis>false</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"emphasis> then this option has no effect."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2435 sssd-ldap.5.xml:2458
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "Default: not specified"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2441
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_ip (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2444
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Space separated list of IPv4 or IPv6 host/network addresses that should be "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"used to filter the rules."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2449
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If this option is empty, SSSD will try to discover the addresses "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"automatically."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2464
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_include_netgroups (boolean)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2467
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"If true then SSSD will download every rule that contains a netgroup in "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"sudoHost attribute."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2482
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ldap_sudo_include_regexp (boolean)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2485
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If true then SSSD will download every rule that contains a wildcard in "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"sudoHost attribute."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2501
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"This manual page only describes attribute name mapping. For detailed "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"explanation of sudo related attribute semantics, see <citerefentry> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<refentrytitle>sudoers.ldap</refentrytitle><manvolnum>5</manvolnum> </"
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"citerefentry>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2511
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "AUTOFS OPTIONS"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2513
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Some of the defaults for the parameters below are dependent on the LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"schema."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2519
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ldap_autofs_map_master_name (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2522
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The name of the automount master map in LDAP."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2525
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: auto.master"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2532
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_map_object_class (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2535
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The object class of an automount map entry in LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2538
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: nisMap (rfc2307, autofs_provider=ad), otherwise automountMap"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2546
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_map_name (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2549
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "The name of an automount map entry in LDAP."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2552
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Default: nisMapName (rfc2307, autofs_provider=ad), otherwise automountMapName"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2560
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_object_class (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2563
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The object class of an automount entry in LDAP. The entry usually "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"corresponds to a mount point."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2568
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: nisObject (rfc2307, autofs_provider=ad), otherwise automount"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2576
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_key (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2579 sssd-ldap.5.xml:2594
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"The key of an automount entry in LDAP. The entry usually corresponds to a "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"mount point."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2583
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Default: cn (rfc2307, autofs_provider=ad), otherwise automountKey"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2591
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_entry_value (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2598
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"Default: nisMapEntry (rfc2307, autofs_provider=ad), otherwise "
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"automountInformation"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2517
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"\"variablelist\" id=\"1\"/> <placeholder type=\"variablelist\" id=\"2\"/> "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"<placeholder type=\"variablelist\" id=\"3\"/> <placeholder type="
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\"variablelist\" id=\"4\"/> <placeholder type=\"variablelist\" id=\"5\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2609
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ADVANCED OPTIONS"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "OPÇÕES AVANÇADAS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2616
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_netgroup_search_base (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_netgroup_search_base (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2621
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_user_search_base (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_user_search_base (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2626
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ldap_group_search_base (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ldap_group_search_base (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2631
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "<note>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><note><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2633
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"If the option <quote>ldap_use_tokengroups</quote> is enabled. The searches "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"against Active Directory will not be restricted and return all groups "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"memberships, even with no gid mapping. It is recommended to disable this "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"feature, if group names are not being displayed correctly."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2640
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "</note>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2642
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_sudo_search_base (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2647
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ldap_autofs_search_base (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2611
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"These options are supported by LDAP domains, but they should be used with "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"caution. Please include them in your configuration only if you know what you "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"are doing. <placeholder type=\"variablelist\" id=\"0\"/> <placeholder type="
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"\"variablelist\" id=\"1\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2664
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following example assumes that SSSD is correctly configured and LDAP is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"set to one of the domains in the <replaceable>[domains]</replaceable> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"section."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2670
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#, no-wrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/LDAP]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_tls_reqcert = demand\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2669 sssd-ldap.5.xml:2687 sssd-simple.5.xml:139
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:725 sssd-ad.5.xml:1000 sssd-sudo.5.xml:56 sssd-sudo.5.xml:98
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:579 include/ldap_id_mapping.xml:105
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<placeholder type=\"programlisting\" id=\"0\"/>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<placeholder type=\"programlisting\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2681
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "LDAP ACCESS FILTER EXAMPLE"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2683
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"The following example assumes that SSSD is correctly configured and to use "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"the ldap_access_order=lockout."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2688
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#, no-wrap
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/LDAP]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"access_provider = ldap\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_access_order = lockout\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_pwdlockout_dn = cn=ppolicy,ou=policies,dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_uri = ldap://ldap.mydomain.org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_search_base = dc=mydomain,dc=org\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ldap_tls_reqcert = demand\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"cache_credentials = true\n"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2703 sssd_krb5_locator_plugin.8.xml:61 sssd-simple.5.xml:148
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ad.5.xml:1015 sssd.8.xml:195 sss_seed.8.xml:163
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "NOTES"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "NOTAS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-ldap.5.xml:2705
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The descriptions of some of the configuration options in this manual page "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are based on the <citerefentry> <refentrytitle>ldap.conf</refentrytitle> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> manual page from the OpenLDAP 2.4 "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"distribution."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refentryinfo>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: pam_sss.8.xml:8 include/upstream.xml:2
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<productname>SSSD</productname> <orgname>The SSSD upstream - http://"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"fedorahosted.org/sssd</orgname>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: pam_sss.8.xml:13 pam_sss.8.xml:18
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "pam_sss"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "pam_sss"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: pam_sss.8.xml:19
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "PAM module for SSSD"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Módulo PAM para SSSD"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: pam_sss.8.xml:24
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>pam_sss.so</command> <arg choice='opt'> <replaceable>quiet</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>forward_pass</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>use_first_pass</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>use_authtok</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='opt'> <replaceable>retry=N</replaceable> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_unknown_user</replaceable> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"arg> <arg choice='opt'> <replaceable>ignore_authinfo_unavail</replaceable> </"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"arg> <arg choice='opt'> <replaceable>domains=X</replaceable> </arg> <arg "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"choice='opt'> <replaceable>allow_missing_name</replaceable> </arg>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:57
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>pam_sss.so</command> is the PAM interface to the System Security "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Services daemon (SSSD). Errors and results are logged through "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<command>syslog(3)</command> with the LOG_AUTHPRIV facility."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:67
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>quiet</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>quiet</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:70
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Suppress log messages for unknown users."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:75
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>forward_pass</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>forward_pass</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:78
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If <option>forward_pass</option> is set the entered password is put on the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"stack for other PAM modules to use."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:85
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>use_first_pass</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>use_first_pass</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:88
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The argument use_first_pass forces the module to use a previous stacked "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"modules password and will never prompt the user - if no password is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"available or the password is not appropriate, the user will be denied access."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:96
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>use_authtok</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>use_authtok</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:99
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When password changing enforce the module to set the new password to the one "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"provided by a previously stacked password module."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:106
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>retry=N</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>retry=N</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:109
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If specified the user is asked another N times for a password if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authentication fails. Default is 0."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:111
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that this option might not work as expected if the application "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"calling PAM handles the user dialog on its own. A typical example is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sshd</command> with <option>PasswordAuthentication</option>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:120
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<option>ignore_unknown_user</option>"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:123
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If this option is specified and the user does not exist, the PAM module will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"return PAM_IGNORE. This causes the PAM framework to ignore this module."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:130
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>ignore_authinfo_unavail</option>"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:134
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Specifies that the PAM module should return PAM_IGNORE if it cannot contact "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"the SSSD daemon. This causes the PAM framework to ignore this module."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:141
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "<option>domains</option>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:145
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Allows the administrator to restrict the domains a particular PAM service is "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"allowed to authenticate against. The format is a comma-separated list of "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"SSSD domain names, as specified in the sssd.conf file."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:151
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"NOTE: Must be used in conjunction with the <quote>pam_trusted_users</quote> "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"and <quote>pam_public_domains</quote> options. Please see the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"manvolnum> </citerefentry> manual page for more information on these two PAM "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"responder options."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:165
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "<option>forward_pass</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>allow_missing_name</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<option>forward_pass</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:169
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The main purpose of this option is to let SSSD determine the user name based "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"on additional information, e.g. the certificate from a Smartcard."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:179
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, no-wrap
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"auth sufficient pam_sss.so allow_missing_name\n"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:174
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The current use case are login managers which can monitor a Smartcard reader "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for card events. In case a Smartcard is inserted the login manager will call "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"a PAM stack which includes a line like <placeholder type=\"programlisting\" "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"id=\"0\"/> In this case SSSD will try to determine the user name based on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"the content of the Smartcard, returns it to pam_sss which will finally put "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"it on the PAM stack."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:191
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "MODULE TYPES PROVIDED"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "MÓDULOS TIPO FORNECIDOS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:192
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"All module types (<option>account</option>, <option>auth</option>, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>password</option> and <option>session</option>) are provided."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:198
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "FILES"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "FICHEIROS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:199
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If a password reset by root fails, because the corresponding SSSD provider "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"does not support password resets, an individual message can be displayed. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This message can e.g. contain instructions about how to reset a password."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:204
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The message is read from the file <filename>pam_sss_pw_reset_message.LOC</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"filename> where LOC stands for a locale string returned by <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>setlocale</refentrytitle><manvolnum>3</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry>. If there is no matching file the content of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<filename>pam_sss_pw_reset_message.txt</filename> is displayed. Root must be "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the owner of the files and only root may have read and write permissions "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"while all other users must have only read permissions."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: pam_sss.8.xml:214
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"These files are searched in the directory <filename>/etc/sssd/customize/"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"DOMAIN_NAME/</filename>. If no matching file is present a generic message is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"displayed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:10 sssd_krb5_locator_plugin.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd_krb5_locator_plugin"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sssd_krb5_locator_plugin"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd_krb5_locator_plugin.8.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Kerberos locator plugin"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:22
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The Kerberos locator plugin <command>sssd_krb5_locator_plugin</command> is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"used by the Kerberos provider of <citerefentry> <refentrytitle>sssd</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>8</manvolnum> </citerefentry> to tell the Kerberos "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"libraries what Realm and which KDC to use. Typically this is done in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> which is always read by the Kerberos libraries. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"To simplify the configuration the Realm and the KDC can be defined in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> as described in <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sssd-krb5</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:48
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"</citerefentry> puts the Realm and the name or IP address of the KDC into "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the environment variables SSSD_KRB5_REALM and SSSD_KRB5_KDC respectively. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"When <command>sssd_krb5_locator_plugin</command> is called by the kerberos "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"libraries it reads and evaluates these variables and returns them to the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"libraries."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:63
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Not all Kerberos implementations support the use of plugins. If "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sssd_krb5_locator_plugin</command> is not available on your system "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"you have to edit /etc/krb5.conf to reflect your Kerberos setup."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd_krb5_locator_plugin.8.xml:69
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If the environment variable SSSD_KRB5_LOCATOR_DEBUG is set to any value "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"debug messages will be sent to stderr."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:10 sssd-simple.5.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd-simple"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sssd-simple"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:17
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "the configuration file for SSSD's 'simple' access-control provider"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:24
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This manual page describes the configuration of the simple access-control "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"provider for <citerefentry> <refentrytitle>sssd</refentrytitle> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<manvolnum>8</manvolnum> </citerefentry>. For a detailed syntax reference, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refer to the <quote>FILE FORMAT</quote> section of the <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> manual page."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:38
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The simple access provider grants or denies access based on an access or "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"deny list of user or group names. The following rules apply:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:43
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "If all lists are empty, access is granted"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:47
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If any list is provided, the order of evaluation is allow,deny. This means "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"that any matching deny rule will supersede any matched allow rule."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:54
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If either or both \"allow\" lists are provided, all users are denied unless "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"they appear in the list."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><itemizedlist><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:60
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If only \"deny\" lists are provided, all users are granted access unless "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"they appear in the list."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:78
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "simple_allow_users (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:81
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Comma separated list of users who are allowed to log in."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:88
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "simple_deny_users (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:91
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Comma separated list of users who are explicitly denied access."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:97
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "simple_allow_groups (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:100
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Comma separated list of groups that are allowed to log in. This applies only "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to groups within this SSSD domain. Local groups are not evaluated."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:108
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "simple_deny_groups (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:111
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Comma separated list of groups that are explicitly denied access. This "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"applies only to groups within this SSSD domain. Local groups are not "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"evaluated."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-simple.5.xml:70 sssd-ipa.5.xml:71 sssd-ad.5.xml:90
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Refer to the section <quote>DOMAIN SECTIONS</quote> of the <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> manual page for details on the configuration of an SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"domain. <placeholder type=\"variablelist\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-simple.5.xml:120
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"Specifying no values for any of the lists is equivalent to skipping it "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"entirely. Beware of this while generating parameters for the simple provider "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"using automated scripts."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:125
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that it is an configuration error if both, simple_allow_users "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"and simple_deny_users, are defined."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:133
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following example assumes that SSSD is correctly configured and example."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This examples shows only the simple access provider-specific options."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-simple.5.xml:140
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#, no-wrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/example.com]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"access_provider = simple\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"simple_allow_users = user1, user2\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sssd-simple.5.xml:150
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The complete group membership hierarchy is resolved before the access check, "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"thus even nested groups can be included in the access lists. Please be "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"aware that the <quote>ldap_group_nesting_level</quote> option may impact the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"results and should be set to a sufficient value. (<citerefentry> "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"citerefentry>) option."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ipa.5.xml:10 sssd-ipa.5.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd-ipa"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ipa.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD IPA provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ipa.5.xml:23
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This manual page describes the configuration of the IPA provider for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ipa.5.xml:36
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The IPA provider is a back end used to connect to an IPA server. (Refer to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the freeipa.org web site for information about IPA servers.) This provider "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"requires that the machine be joined to the IPA domain; configuration is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"almost entirely self-discovered and obtained directly from the server."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-ipa.5.xml:43
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The IPA provider accepts the same options used by the <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> identity provider and the <citerefentry> <refentrytitle>sssd-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> authentication "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider with some exceptions described below."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#: sssd-ipa.5.xml:55
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"However, it is neither necessary nor recommended to set these options. IPA "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider can also be used as an access and chpass provider. As an access "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider it uses HBAC (host-based access control) rules. Please refer to "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"freeipa.org for more information about HBAC. No configuration of access "
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"provider is required on the client side."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:62
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The IPA provider will use the PAC responder if the Kerberos tickets of users "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"from trusted realms contain a PAC. To make configuration easier the PAC "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"responder is started automatically if the IPA ID provider is configured."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:78
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipa_domain (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ipa_domain (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:81
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specifies the name of the IPA domain. This is optional. If not provided, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the configuration domain name is used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:89
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ipa_server, ipa_backup_server (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:92
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The comma-separated list of IP addresses or hostnames of the IPA servers to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"which SSSD should connect in the order of preference. For more information "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"on failover and server redundancy, see the <quote>FAILOVER</quote> section. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This is optional if autodiscovery is enabled. For more information on "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:105
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipa_hostname (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ipa_hostname (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:108
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Optional. May be set on machines where the hostname(5) does not reflect the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"fully qualified name used in the IPA domain to identify this host."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:116 sssd-ad.5.xml:817
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_update (boolean)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-ipa.5.xml:119
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Optional. This option tells SSSD to automatically update the DNS server "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"built into FreeIPA with the IP address of this client. The update is secured "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"using GSS-TSIG. The IP address of the IPA LDAP connection is used for the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"updates, if it is not otherwise specified by using the <quote>dyndns_iface</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"quote> option."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:128 sssd-ad.5.xml:831
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"NOTE: On older systems (such as RHEL 5), for this behavior to work reliably, "
056302a92862fda16351d7192600746746f38e5dStephen Gallagher"the default Kerberos realm must be set properly in /etc/krb5.conf"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:133
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_update</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_update</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:145 sssd-ad.5.xml:842
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_ttl (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:148 sssd-ad.5.xml:845
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The TTL to apply to the client DNS record when updating it. If "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"dyndns_update is false this has no effect. This will override the TTL "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"serverside if set by an administrator."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:153
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_ttl</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_ttl</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#: sssd-ipa.5.xml:159
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Default: 1200 (seconds)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:165 sssd-ad.5.xml:856
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_iface (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:168 sssd-ad.5.xml:859
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Optional. Applicable only when dyndns_update is true. Choose the interface "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"or a list of interfaces whose IP addresses should be used for dynamic DNS "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"updates. Special value <quote>*</quote> implies that IPs from all interfaces "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"should be used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:175
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"NOTE: While it is still possible to use the old <emphasis>ipa_dyndns_iface</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> option, users should migrate to using <emphasis>dyndns_iface</"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"emphasis> in their config file."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:181
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for IPA LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"connection"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:185 sssd-ad.5.xml:870
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Example: dyndns_iface = em1, vnet1, vnet2"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:191
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "ipa_enable_dns_sites (boolean)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:194 sssd-ad.5.xml:187
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Enables DNS sites - location based service discovery."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:198
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"If true and service discovery (see Service Discovery paragraph at the bottom "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"of the man page) is enabled, then the SSSD will first attempt location "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"based discovery using a query that contains \"_location.hostname.example.com"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"\" and then fall back to traditional SRV discovery. If the location based "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"discovery succeeds, the IPA servers located with the location based "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"discovery are treated as primary servers and the IPA servers located using "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"the traditional SRV discovery are used as back up servers"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:217 sssd-ad.5.xml:876
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_refresh_interval (integer)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:220 sssd-ad.5.xml:879
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"How often should the back end perform periodic DNS update in addition to the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"automatic update performed when the back end goes online. This option is "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"optional and applicable only when dyndns_update is true."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:233 sssd-ad.5.xml:892
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_update_ptr (bool)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:236 sssd-ad.5.xml:895
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Whether the PTR record should also be explicitly updated when updating the "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"client's DNS records. Applicable only when dyndns_update is true."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:241
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"This option should be False in most IPA deployments as the IPA server "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"generates the PTR records automatically when forward records are changed."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:247
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: False (disabled)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:253 sssd-ad.5.xml:906
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "dyndns_force_tcp (bool)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:256 sssd-ad.5.xml:909
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Whether the nsupdate utility should default to using TCP for communicating "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"with the DNS server."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:260 sssd-ad.5.xml:913
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: False (let nsupdate choose the protocol)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:266 sssd-ad.5.xml:919
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "id_provider (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "dyndns_server (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "id_provider (string)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:269 sssd-ad.5.xml:922
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"The DNS server to use when performing a DNS update. In most setups, it's "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"recommended to leave this option unset."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:274 sssd-ad.5.xml:927
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Setting this option makes sense for environments where the DNS server is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"different from the identity server."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:279 sssd-ad.5.xml:932
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Please note that this option will be only used in fallback attempt when "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"previous attempt using autodetected settings failed."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:284 sssd-ad.5.xml:937
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: None (let nsupdate choose the server)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:290
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "ipa_hbac_search_base (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ipa_hbac_search_base (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:293
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Optional. Use the given string as search base for HBAC related objects."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:297
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: Use base DN"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Default: Use base DN"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:303
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ipa_host_search_base (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:306
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Optional. Use the given string as search base for host objects."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:310 sssd-ipa.5.xml:329 sssd-ipa.5.xml:348 sssd-ipa.5.xml:367
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:386
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"See <quote>ldap_search_base</quote> for information about configuring "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"multiple search bases."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:315 sssd-ipa.5.xml:334 include/ldap_search_bases.xml:27
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: the value of <emphasis>ldap_search_base</emphasis>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:322
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "ipa_selinux_search_base (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:325
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid "Optional. Use the given string as search base for SELinux user maps."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:341
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ipa_subdomains_search_base (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:344
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Optional. Use the given string as search base for trusted domains."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:353
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Default: the value of <emphasis>cn=trusts,%basedn</emphasis>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:360
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "ipa_master_domain_search_base (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:363
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Optional. Use the given string as search base for master domain object."
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:372
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgid "Default: the value of <emphasis>cn=ad,cn=etc,%basedn</emphasis>"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallaghermsgstr ""
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:379
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_views_search_base (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:382
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Optional. Use the given string as search base for views containers."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:391
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: the value of <emphasis>cn=views,cn=accounts,%basedn</emphasis>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:398 sssd-krb5.5.xml:254
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_validate (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_validate (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:401
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Verify with the help of krb5_keytab that the TGT obtained has not been "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"spoofed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:408 sssd-ad.5.xml:958
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Note that this default differs from the traditional Kerberos provider back "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"end."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:418
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The name of the Kerberos realm. This is optional and defaults to the value "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"of <quote>ipa_domain</quote>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:422
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The name of the Kerberos realm has a special meaning in IPA - it is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"converted into the base DN to use for performing LDAP operations."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:433
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host and user principal should be canonicalized when "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"connecting to IPA LDAP and also for AS requests. This feature is available "
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher"with MIT Kerberos >= 1.7"
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:446 sssd-krb5.5.xml:416
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "krb5_use_fast (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:449 sssd-krb5.5.xml:419
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Enables flexible authentication secure tunneling (FAST) for Kerberos pre-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"authentication. The following options are supported:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:454
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>never</emphasis> use FAST."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:457
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"continue the authentication without it. This is equivalent to not setting "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"this option at all."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:463 sssd-krb5.5.xml:433
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>demand</emphasis> to use FAST. The authentication fails if the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"server does not require fast."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:468
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: try"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:471 sssd-krb5.5.xml:444
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: SSSD supports FAST only with MIT Kerberos version 1.8 and later. If "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD is used with an older version of MIT Kerberos, using this option is a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"configuration error."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:480 sssd-ad.5.xml:965
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "krb5_confd_path (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:483 sssd-ad.5.xml:968
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Absolute path of a directory where SSSD should place Kerberos configuration "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"snippets."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:487 sssd-ad.5.xml:972
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"To disable the creation of the configuration snippets set the parameter to "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"'none'."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:491 sssd-ad.5.xml:976
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Default: not set (krb5.include.d subdirectory of SSSD's pubconf directory)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:498
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_hbac_refresh (integer)"
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgstr ""
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:501
e0882baf3b0174cd5c34d593442f66bf6ff75261Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The amount of time between lookups of the HBAC rules against the IPA server. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This will reduce the latency and load on the IPA server if there are many "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"access-control requests made in a short period."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ipa.5.xml:508 sssd-ipa.5.xml:524 sssd-ad.5.xml:382
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: 5 (seconds)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:514
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_hbac_selinux (integer)"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgstr ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:517
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The amount of time between lookups of the SELinux maps against the IPA "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"server. This will reduce the latency and load on the IPA server if there are "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"many user login requests made in a short period."
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:530
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_server_mode (boolean)"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:533
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "This option should only be set by the IPA installer."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:537
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The option denotes that the SSSD is running on IPA server and should perform "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"lookups of users and groups from trusted domains differently."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:548
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ipa_automount_location (string)"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:551
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "The automounter location this IPA client will be using"
056302a92862fda16351d7192600746746f38e5dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
056302a92862fda16351d7192600746746f38e5dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:554
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: The location named \"default\""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:562
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "VIEWS AND OVERRIDES"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:571
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_view_class (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:574
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Objectclass of the view container."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:577
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: nsContainer"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:583
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_view_name (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:586
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Name of the attribute holding the name of the view."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:596
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_overide_object_class (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:599
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Objectclass of the override objects."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:602
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaOverrideAnchor"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:608
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_anchor_uuid (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:611
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the attribute containing the reference to the original object in a "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"remote domain."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:615
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaAnchorUUID"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:621
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_user_override_object_class (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:624
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the objectclass for user overrides. It is used to determine if the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"found override object is related to a user or a group."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:629
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "User overrides can contain attributes given by"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:632
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_name"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:635
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_uid_number"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:638
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_gid_number"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:641
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_gecos"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:644
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_home_directory"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:647
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_user_shell"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:650
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "ldap_user_ssh_public_key"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:655
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaUserOverride"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><term>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:661
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ipa_group_override_object_class (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:664
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"Name of the objectclass for group overrides. It is used to determine if the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"found override object is related to a user or a group."
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:669
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Group overrides can contain attributes given by"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:672
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_group_name"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:675
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "ldap_group_gid_number"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:680
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "Default: ipaGroupOverride"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:564
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"SSSD can handle views and overrides which are offered by FreeIPA 4.1 and "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"later version. Since all paths and objectclasses are fixed on the server "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"side there is basically no need to configure anything. For completeness the "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"related options are listed here with their default values. <placeholder "
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek"type=\"variablelist\" id=\"0\"/>"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:690
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "SUBDOMAINS PROVIDER"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:692
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The IPA subdomains provider behaves slightly differently if it is configured "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"explicitly or implicitly."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:696
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If the option 'subdomains_provider = ipa' is found in the domain section of "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"sssd.conf, the IPA subdomains provider is configured explicitly, and all "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"subdomain requests are sent to the IPA server if necessary."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:702
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"If the option 'subdomains_provider' is not set in the domain section of sssd."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"conf but there is the option 'id_provider = ipa', the IPA subdomains "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"provider is configured implicitly. In this case, if a subdomain request "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"fails and indicates that the server does not support subdomains, i.e. is not "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"configured for trusts, the IPA subdomains provider is disabled. After an "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"hour or after the IPA provider goes online, the subdomains provider is "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"enabled again."
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:719
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following example assumes that SSSD is correctly configured and example."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This examples shows only the ipa provider-specific options."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ipa.5.xml:726
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/example.com]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"id_provider = ipa\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ipa_server = ipaserver.example.com\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ipa_hostname = myhost.example.com\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:10 sssd-ad.5.xml:16
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "sssd-ad"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ad.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD Active Directory provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:23
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This manual page describes the configuration of the AD provider for "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:36
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider is a back end used to connect to an Active Directory server. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This provider requires that the machine be joined to the AD domain and a "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"keytab is available."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:41
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider supports connecting to Active Directory 2008 R2 or later. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Earlier versions may work, but are unsupported."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: sssd-ad.5.xml:45
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The AD provider can be used to get user information and authenticate users "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from trusted domains. Currently only trusted domains in the same forest are "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"recognized. In addition servers from trusted domains are always auto-"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"discovered."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:51
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The AD provider accepts the same options used by the <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry> identity provider and the <citerefentry> <refentrytitle>sssd-"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"krb5</refentrytitle> <manvolnum>5</manvolnum> </citerefentry> authentication "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"provider with some exceptions described below."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:63
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"However, it is neither necessary nor recommended to set these options. The "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"AD provider can also be used as an access, chpass, sudo and autofs provider. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"No configuration of the access provider is required on the client side."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:75
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_id_mapping = False\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek" "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:69
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"By default, the AD provider will map UID and GID values from the objectSID "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"parameter in Active Directory. For details on this, see the <quote>ID "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"MAPPING</quote> section below. If you want to disable ID mapping and instead "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"rely on POSIX attributes defined in Active Directory, you should set "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/> In order to retrieve users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"and groups using POSIX attributes from trusted domains, the AD administrator "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must make sure that the POSIX attributes are replicated to the Global "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Catalog."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:82
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Users, groups and other entities served by SSSD are always treated as case-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"insensitive in the AD provider for compatibility with Active Directory's "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"LDAP implementation."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:97
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ad_domain (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:100
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"Specifies the name of the Active Directory domain. This is optional. If not "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"provided, the configuration domain name is used."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:105
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"For proper operation, this option should be specified as the lower-case "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"version of the long version of the Active Directory domain."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:110
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgid ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"The short domain name (also known as the NetBIOS or the flat name) is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"autodetected by the SSSD."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sssd-ad.5.xml:117
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#, fuzzy
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#| msgid "ipa_domain (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "ad_enabled_domains (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr "ipa_domain (string)"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:120
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"A comma-separated list of enabled Active Directory domains. If provided, "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"SSSD will ignore any domains not listed in this option. If left unset, all "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"domains from the AD forest will be available."
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:130
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#, no-wrap
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"ad_enabled_domains = sales.example.com, eng.example.com\n"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek" "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:126
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"For proper operation, this option must be specified in all lower-case and as "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"the fully qualified domain name of the Active Directory domain. For example: "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:134
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"The short domain name (also known as the NetBIOS or the flat name) will be "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"autodetected by SSSD."
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:138 sssd-ad.5.xml:260 sssd-ad.5.xml:274
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid "Default: Not set"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:144
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "ad_server, ad_backup_server (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:147
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"The comma-separated list of hostnames of the AD servers to which SSSD should "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"connect in order of preference. For more information on failover and server "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"redundancy, see the <quote>FAILOVER</quote> section."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:154
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This is optional if autodiscovery is enabled. For more information on "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"service discovery, refer to the <quote>SERVICE DISCOVERY</quote> section."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:159
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Trusted domains will always auto-discover servers even if the primary "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"server is explicitly defined in the ad_server option."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:167
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid "ad_hostname (string)"
7797e361155f7ce937085fd98e360469d7baf1b6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:170
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Optional. May be set on machines where the hostname(5) does not reflect the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"fully qualified name used in the Active Directory domain to identify this "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"host."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:176
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This field is used to determine the host principal in use in the keytab. It "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must match the hostname for which the keytab was issued."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:184
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_enable_dns_sites (boolean)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:191
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If true and service discovery (see Service Discovery paragraph at the bottom "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"of the man page) is enabled, the SSSD will first attempt to discover the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Active Directory server to connect to using the Active Directory Site "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Discovery and fall back to the DNS SRV records if no AD site is found. The "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"DNS SRV configuration, including the discovery domain, is used during site "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"discovery as well."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:207
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_access_filter (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:210
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option specifies LDAP access control filter that the user must match in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"order to be allowed access. Please note that the <quote>access_provider</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> option must be explicitly set to <quote>ad</quote> in order for this "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"option to have an effect."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:218
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The option also supports specifying different filters per domain or forest. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This extended filter would consist of: <quote>KEYWORD:NAME:FILTER</quote>. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The keyword can be either <quote>DOM</quote>, <quote>FOREST</quote> or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"missing."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:226
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If the keyword equals to <quote>DOM</quote> or is missing, then <quote>NAME</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"quote> specifies the domain or subdomain the filter applies to. If the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"keyword equals to <quote>FOREST</quote>, then the filter equals to all "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domains from the forest specified by <quote>NAME</quote>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:234
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Multiple filters can be separated with the <quote>?</quote> character, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"similarly to how search bases work."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:239
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The most specific match is always used. For example, if the option specified "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"filter for a domain the user is a member of and a global filter, the per-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain filter would be applied. If there are more matches with the same "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"specification, the first one is used."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:250
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#, no-wrap
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on domain called dom1 only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"dom1:(memberOf=cn=admins,ou=groups,dc=dom1,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on domain called dom2 only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"DOM:dom2:(memberOf=cn=admins,ou=groups,dc=dom2,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"# apply filter on forest called EXAMPLE.COM only:\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"FOREST:EXAMPLE.COM:(memberOf=cn=admins,ou=groups,dc=example,dc=com)\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:266
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "ad_site (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:269
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Specify AD site to which client should try to connect. If this option is "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"not provided, the AD site will be auto-discovered."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:280
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_enable_gc (boolean)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:283
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"By default, the SSSD connects to the Global Catalog first to retrieve users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"from trusted domains and uses the LDAP port to retrieve group memberships or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"as a fallback. Disabling this option makes the SSSD only connect to the LDAP "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"port of the current AD server."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:291
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that disabling Global Catalog support does not disable "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"retrieving users from trusted domains. The SSSD would connect to the LDAP "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"port of trusted domains instead. However, Global Catalog must be used in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"order to resolve cross-domain group memberships."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:305
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "ad_gpo_access_control (string)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:308
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This option specifies the operation mode for GPO-based access control "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"functionality: whether it operates in disabled mode, enforcing mode, or "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permissive mode. Please note that the <quote>access_provider</quote> option "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"must be explicitly set to <quote>ad</quote> in order for this option to have "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"an effect."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:317
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"GPO-based access control functionality uses GPO policy settings to determine "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"whether or not a particular user is allowed to logon to a particular host."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:323
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: If the operation mode is set to enforcing, it is possible that users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that were previously allowed logon access will now be denied logon access "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"(as dictated by the GPO policy settings). In order to facilitate a smooth "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"transition for administrators, a permissive mode is available that will not "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"enforce the access control rules, but will evaluate them and will output a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"syslog message if access would have been denied. By examining the logs, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"administrators can then make the necessary changes before setting the mode "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"to enforcing."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:336
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "There are three supported values for this option:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:340
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"disabled: GPO-based access control rules are neither evaluated nor enforced."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:346
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "enforcing: GPO-based access control rules are evaluated and enforced."
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:352
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"permissive: GPO-based access control rules are evaluated, but not enforced. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Instead, a syslog message will be emitted indicating that the user would "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"have been denied access if this option's value were set to enforcing."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:363
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: permissive"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:366
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "Default: enforcing"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:372
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_cache_timeout (integer)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:375
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The amount of time between lookups of GPO policy files against the AD "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"server. This will reduce the latency and load on the AD server if there are "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"many access-control requests made in a short period."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:388
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_interactive (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:391
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the InteractiveLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyInteractiveLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:397
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on locally\" and \"Deny log on locally\"."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:411
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_interactive = +my_pam_service, -login\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:402
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>login</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:415 sssd-ad.5.xml:511 sssd-ad.5.xml:557 sssd-ad.5.xml:602
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:668
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: the default set of PAM service names includes:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:419
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "login"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:424
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "su"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:429
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "su-l"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:434
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-fingerprint"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:439
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-password"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:444
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "gdm-smartcard"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:449
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "kdm"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:454
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "lightdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:459
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "lxdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:464
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "sddm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:469
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "unity"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:474
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "xdm"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:483
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_remote_interactive (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:486
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the RemoteInteractiveLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyRemoteInteractiveLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:492
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"log on through Remote Desktop Services\" and \"Deny log on through Remote "
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek"Desktop Services\"."
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:507
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_remote_interactive = +my_pam_service, -sshd\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:498
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>sshd</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:515
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sshd"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:520
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "cockpit"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:529
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_network (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:532
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the NetworkLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyNetworkLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:538
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Access "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"this computer from the network\" and \"Deny access to this computer from the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"network\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:553
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_network = +my_pam_service, -ftp\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:544
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>ftp</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:561
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ftp"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:566
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "samba"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:575
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_batch (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:578
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the BatchLogonRight and DenyBatchLogonRight "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:584
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on as a batch job\" and \"Deny log on as a batch job\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:598
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_batch = +my_pam_service, -crond\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:589
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for this logon right (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>crond</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:606
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "crond"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:615
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_service (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:618
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"control is evaluated based on the ServiceLogonRight and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"DenyServiceLogonRight policy settings."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:624
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Note: Using the Group Policy Management Editor this value is called \"Allow "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"log on as a service\" and \"Deny log on as a service\"."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:637
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_service = +my_pam_service\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:629 sssd-ad.5.xml:704
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add a PAM service name to the default set by using <quote>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"+service_name</quote>. Since the default set is empty, it is not possible "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"to remove a PAM service name from the default set. For example, in order to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"add a custom pam service name (e.g. <quote>my_pam_service</quote>), you "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"would use the following configuration: <placeholder type=\"programlisting\" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:647
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_permit (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:650
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always granted, regardless of any GPO Logon Rights."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:664
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_permit = +my_pam_service, -sudo\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:655
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"It is possible to add another PAM service name to the default set by using "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>+service_name</quote> or to explicitly remove a PAM service name from "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"the default set by using <quote>-service_name</quote>. For example, in "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"order to replace a default PAM service name for unconditionally permitted "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"access (e.g. <quote>sudo</quote>) with a custom pam service name (e.g. "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>my_pam_service</quote>), you would use the following configuration: "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:672
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "polkit-1"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:677
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sudo"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:682
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sudo-i"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:687
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "systemd-user"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:696
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_map_deny (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:699
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"A comma-separated list of PAM service names for which GPO-based access is "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always denied, regardless of any GPO Logon Rights."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:712
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"ad_gpo_map_deny = +my_pam_service\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek" "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:722
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "ad_gpo_default_right (string)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:725
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"This option defines how access control is evaluated for PAM service names "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"that are not explicitly listed in one of the ad_gpo_map_* options. This "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"option can be set in two different manners. First, this option can be set to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"use a default logon right. For example, if this option is set to "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"'interactive', it means that unmapped PAM service names will be processed "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"based on the InteractiveLogonRight and DenyInteractiveLogonRight policy "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"settings. Alternatively, this option can be set to either always permit or "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"always deny access for unmapped PAM service names."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:738
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Supported values for this option include:"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:742
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "interactive"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:747
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "remote_interactive"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:752
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "network"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:757
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "batch"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:762
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "service"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:767
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "permit"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><itemizedlist><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:772
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "deny"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:778
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Default: deny"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:784
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_maximum_machine_account_password_age (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:787
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"SSSD will check once a day if the machine account password is older than the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"given age in days and try to renew it. A value of 0 will disable the renewal "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"attempt."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:793
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "Default: 300"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 30 days"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "Padrão: 300"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:799
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ad_machine_account_password_renewal_opts (string)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:802
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"This option should only be used to test the machine account renewal task. "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"The option expect 2 integers seperated by a colon (':'). The first integer "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"defines the interval in seconds how often the task is run. The second "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"specifies the inital timeout in seconds before the task is run for the first "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"time after startup."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:811
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "Default: 86400 (24 hours)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Default: 86400:750 (24h and 15m)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "Padrão: 86400 (24 horas)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:820
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Optional. This option tells SSSD to automatically update the Active "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"Directory DNS server with the IP address of this client. The update is "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"secured using GSS-TSIG. As a consequence, the Active Directory administrator "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"only needs to allow secure updates for the DNS zone. The IP address of the "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"AD LDAP connection is used for the updates, if it is not otherwise specified "
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek"by using the <quote>dyndns_iface</quote> option."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:850
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: 3600 (seconds)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:866
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Default: Use the IP addresses of the interface which is used for AD LDAP "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"connection"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:900 sss_rpcidmapd.5.xml:76
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgid "Default: True"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr "Padrão: TRUE"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:946 sssd-krb5.5.xml:505
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "krb5_use_enterprise_principal (boolean)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:949 sssd-krb5.5.xml:508
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Specifies if the user principal should be treated as enterprise principal. "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"See section 5 of RFC 6806 for more details about enterprise principals."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:994
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"The following example assumes that SSSD is correctly configured and example."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"com is one of the domains in the <replaceable>[sssd]</replaceable> section. "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"This example shows only the AD provider-specific options."
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:1001
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#, no-wrap
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"[domain/EXAMPLE]\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"id_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"auth_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"access_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"chpass_provider = ad\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_server = dc1.example.com\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_hostname = client.example.com\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"ad_domain = example.com\n"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:1021
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#, no-wrap
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"access_provider = ldap\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_access_order = expire\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"ldap_account_expire_policy = ad\n"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:1017
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"The AD access control provider checks if the account is expired. It has the "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"same effect as the following configuration of the LDAP provider: "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:1027
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"However, unless the <quote>ad</quote> access control provider is explicitly "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"configured, the default access provider is <quote>permit</quote>. Please "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"note that if you configure an access provider other than <quote>ad</quote>, "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"you need to set all the connection parameters (such as LDAP URIs and "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"encryption details) manually."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-ad.5.xml:1035
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"When the autofs provider is set to <quote>ad</quote>, the RFC2307 schema "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"attribute mapping (nisMap, nisObject, ...) is used, because these attributes "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"are included in the default Active Directory schema."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:10 sssd-sudo.5.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sssd-sudo"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek#: sssd-sudo.5.xml:17
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "Configuring sudo with the SSSD back end"
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgstr ""
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:23
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This manual page describes how to configure <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sudo</refentrytitle> <manvolnum>8</manvolnum> </citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"to work with <citerefentry> <refentrytitle>sssd</refentrytitle> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<manvolnum>8</manvolnum> </citerefentry> and how SSSD caches sudo rules."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:36
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Configuring sudo to cooperate with SSSD"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:38
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"To enable SSSD as a source for sudo rules, add <emphasis>sss</emphasis> to "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"the <emphasis>sudoers</emphasis> entry in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>nsswitch.conf</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:47
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"For example, to configure sudo to first lookup rules in the standard "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<citerefentry> <refentrytitle>sudoers</refentrytitle> <manvolnum>5</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"manvolnum> </citerefentry> file (which should contain rules that apply to "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"local users) and then in SSSD, the nsswitch.conf file should contain the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"following line:"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:57
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sudoers: files sss\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd-sudo.5.xml:61
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"More information about configuring the sudoers search order from the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"nsswitch.conf file as well as information about the LDAP schema that is used "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"to store sudo rules in the directory can be found in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sudoers.ldap</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:70
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: in order to use netgroups or IPA hostgroups in "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"sudo rules, you also need to correctly set <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>nisdomainname</refentrytitle> <manvolnum>1</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> to your NIS domain name (which equals to IPA domain name when "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"using hostgroups)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:82
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Configuring SSSD to fetch sudo rules"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:84
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"All configuration that is needed on SSSD side is to extend the list of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>services</emphasis> with \"sudo\" in [sssd] section of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry>. To speed up the LDAP lookups, you can also set "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"search base for sudo rules using <emphasis>ldap_sudo_search_base</emphasis> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"option."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:94
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The following example shows how to configure SSSD to download sudo rules "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"from an LDAP server."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:99
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#, no-wrap
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"[sssd]\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"config_file_version = 2\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"services = nss, pam, sudo\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"domains = EXAMPLE\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"[domain/EXAMPLE]\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"id_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"sudo_provider = ldap\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_uri = ldap://example.com\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"ldap_sudo_search_base = ou=sudoers,dc=example,dc=com\n"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-sudo.5.xml:112
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"When SSSD is configured to use IPA as the ID provider, the sudo provider is "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"automatically enabled. The sudo search base is configured to use the IPA "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"native LDAP tree (cn=sudo,$SUFFIX). If any other search base is defined in "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"sssd.conf, this value will be used instead. The compat tree (ou=sudoers,"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"$SUFFIX) is no longer required for IPA sudo functionality."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:122
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "The SUDO rule caching mechanism"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:124
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The biggest challenge, when developing sudo support in SSSD, was to ensure "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"that running sudo with SSSD as the data source provides the same user "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"experience and is as fast as sudo but keeps providing the most current set "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"of rules as possible. To satisfy these requirements, SSSD uses three kinds "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"of updates. They are referred to as full refresh, smart refresh and rules "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refresh."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:132
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>smart refresh</emphasis> periodically downloads rules that are "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"new or were modified after the last update. Its primary goal is to keep the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"database growing by fetching only small increments that do not generate "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"large amounts of network traffic."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:138
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>full refresh</emphasis> simply deletes all sudo rules stored "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"in the cache and replaces them with all rules that are stored on the server. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This is used to keep the cache consistent by removing every rule which was "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"deleted from the server. However, full refresh may produce a lot of traffic "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"and thus it should be run only occasionally depending on the size and "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"stability of the sudo rules."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:146
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The <emphasis>rules refresh</emphasis> ensures that we do not grant the user "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"more permission than defined. It is triggered each time the user runs sudo. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Rules refresh will find all rules that apply to this user, check their "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"expiration time and redownload them if expired. In the case that any of "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"these rules are missing on the server, the SSSD will do an out of band full "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refresh because more rules (that apply to other users) may have been deleted."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:155
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"If enabled, SSSD will store only rules that can be applied to this machine. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"This means rules that contain one of the following values in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>sudoHost</emphasis> attribute:"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:162
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "keyword ALL"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:167
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozekmsgid "wildcard"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:172
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "netgroup (in the form \"+netgroup\")"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:177
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "hostname or fully qualified domain name of this machine"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:182
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "one of the IP addresses of this machine"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><itemizedlist><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:187
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "one of the IP addresses of the network (in the form \"address/mask\")"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-sudo.5.xml:193
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"There are many configuration options that can be used to adjust the "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"behavior. Please refer to \"ldap_sudo_*\" in <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry> and \"sudo_*\" in <citerefentry> <refentrytitle>sssd.conf</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:10 sssd.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sssd"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "System Security Services Daemon"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Daemon de serviços de segurança do sistema"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sssd</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sssd</command> <arg choice='opt'> <replaceable>options</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> </arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:31
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>SSSD</command> provides a set of daemons to manage access to remote "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"directories and authentication mechanisms. It provides an NSS and PAM "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"interface toward the system and a pluggable backend system to connect to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"multiple different account sources as well as D-Bus interface. It is also "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the basis to provide client auditing and policy services for projects like "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"FreeIPA. It provides a more robust database to store local users as well as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"extended user data."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:46
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<option>-d</option>,<option>--debug-level</option> <replaceable>LEVEL</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:53
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:57
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>1</emphasis>: Add a timestamp to the debug messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:60
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>0</emphasis>: Disable timestamp in the debug messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:69
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>--debug-microseconds=</option><replaceable>mode</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:73
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<emphasis>1</emphasis>: Add microseconds to the timestamp in debug messages"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:76
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<emphasis>0</emphasis>: Disable microseconds in timestamp"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:85
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-f</option>,<option>--debug-to-files</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-f</option>,<option>--debug-to-files</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:89
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Send the debug output to files instead of stderr. By default, the log files "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"are stored in <filename>/var/log/sssd</filename> and there are separate log "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"files for every SSSD service and domain."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:97
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-D</option>,<option>--daemon</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-D</option>,<option>--daemon</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:101
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Become a daemon after starting up."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Tornar-se um daemon após a instalação."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sssd.8.xml:107 sss_seed.8.xml:136
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-i</option>,<option>--interactive</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-i</option>,<option>--interactive</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd.8.xml:111
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Run in the foreground, don't become a daemon."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Executar em primeiro plano, não se torne um daemon."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:117 sss_debuglevel.8.xml:42
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-c</option>,<option>--config</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-c</option>,<option>--config</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:121 sss_debuglevel.8.xml:46
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Specify a non-default config file. The default is <filename>/etc/sssd/sssd."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"conf</filename>. For reference on the config file syntax and options, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"consult the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<manvolnum>5</manvolnum> </citerefentry> manual page."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:135
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "<option>--version</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>--version</option>"
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:139
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallaghermsgid "Print version number and exit."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Imprimir o número da versão e sair."
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:147
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Signals"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Sinais"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:150
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SIGTERM/SIGINT"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SIGTERM/SIGINT"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:153
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Informs the SSSD to gracefully terminate all of its child processes and then "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"shut down the monitor."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:159
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SIGHUP"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SIGHUP"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:162
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Tells the SSSD to stop writing to its current debug file descriptors and to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"close and reopen them. This is meant to facilitate log rolling with programs "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"like logrotate."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:170
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SIGUSR1"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SIGUSR1"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:173
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Tells the SSSD to simulate offline operation for the duration of the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<quote>offline_timeout</quote> parameter. This is useful for testing. The "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"signal can be sent to either the sssd process or any sssd_be process "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"directly."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:182
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SIGUSR2"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "SIGUSR2"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:185
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Tells the SSSD to go online immediately. This is useful for testing. The "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"signal can be sent to either the sssd process or any sssd_be process "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"directly."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd.8.xml:197
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"If the environment variable SSS_NSS_USE_MEMCACHE is set to \"NO\", client "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"applications will not use the fast in memory cache."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:10 sss_obfuscate.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_obfuscate"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sss_obfuscate"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "obfuscate a clear text password"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "ofuscar uma senha de texto não criptografado"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable></arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_obfuscate</command> <arg choice='opt'> <replaceable>options</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>[PASSWORD]</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable></arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_obfuscate</command> converts a given password into human-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"unreadable format and places it into appropriate domain section of the SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"config file."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:37
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The cleartext password is read from standard input or entered "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"interactively. The obfuscated password is put into "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>ldap_default_authtok</quote> parameter of a given SSSD domain and the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>ldap_default_authtok_type</quote> parameter is set to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<quote>obfuscated_password</quote>. Refer to <citerefentry> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<refentrytitle>sssd-ldap</refentrytitle> <manvolnum>5</manvolnum> </"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"citerefentry> for more details on these parameters."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:49
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that obfuscating the password provides <emphasis>no real "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"security benefit</emphasis> as it is still possible for an attacker to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"reverse-engineer the password back. Using better authentication mechanisms "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"such as client side certificates or GSSAPI is <emphasis>strongly</emphasis> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"advised."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:63
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-s</option>,<option>--stdin</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-s</option>,<option>--stdin</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:67
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The password to obfuscate will be read from standard input."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_obfuscate.8.xml:74 sss_ssh_authorizedkeys.1.xml:70
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:78
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:79
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The SSSD domain to use the password in. The default name is <quote>default</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"quote>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:86
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:91
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Read the config file specified by the positional parameter."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_obfuscate.8.xml:95
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: <filename>/etc/sssd/sssd.conf</filename>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:10 sss_override.8.xml:15
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "sss_usermod"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "sss_override"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "sss_usermod"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:16
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "create local overrides of user and group attributes"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:21
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "<command>sss_usermod</command> <arg choice='opt'> <replaceable>options</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| "arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_override</command> <arg choice='plain'><replaceable>COMMAND</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_usermod</command> <arg choice='opt'> <replaceable>options</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"arg>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:32
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<command>sss_override</command> enables to create a client-side view and "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"allows to change selected values of specific user and groups. This change "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"takes effect only on local machine."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sss_override.8.xml:37
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Overrides data are stored in the SSSD cache. If the cache is deleted, all "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"local overrides are lost. Please note that after the first override is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"created using any of the following <emphasis>user-add</emphasis>, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>group-add</emphasis>, <emphasis>user-import</emphasis> or "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>group-import</emphasis> command. SSSD needs to be restarted to "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"take effect. <emphasis>sss_override</emphasis> prints message when a "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"restart is required."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sss_override.8.xml:50 sssctl.8.xml:41
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "AVAILABLE COMMANDS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:52
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Argument <emphasis>NAME</emphasis> is the name of original object in all "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"commands. It is not possible to override <emphasis>uid</emphasis> or "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<emphasis>gid</emphasis> to 0."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:59
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<option>user-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"name</option> NAME</optional> <optional><option>-u,--uid</option> UID</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optional> <optional><option>-g,--gid</option> GID</optional> "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<optional><option>-h,--home</option> HOME</optional> <optional><option>-s,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"shell</option> SHELL</optional> <optional><option>-c,--gecos</option> GECOS</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional> <optional><option>-x,--certificate</option> BASE64 ENCODED "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"CERTIFICATE</optional>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:72
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Override attributes of an user. Please be aware that calling this command "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"will replace any previous override for the (NAMEd) user."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:80
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-del</option> <emphasis>NAME</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:85
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Remove user overrides. However be aware that overridden attributes might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"returned from memory cache. Please see SSSD option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:94
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>user-find</option> <optional><option>-d,--domain</option> DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:99
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"List all users with set overrides. If <emphasis>DOMAIN</emphasis> parameter "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"is set, only users from the domain are listed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:107
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>user-show</option> <emphasis>NAME</emphasis>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:112
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Show user overrides."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:118
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-import</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:123
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Import user overrides from <emphasis>FILE</emphasis>. Data format is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"similar to standard passwd file. The format is:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:128
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "original_name:name:uid:gid:gecos:home:shell:base64_encoded_certificate"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:131
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"where original_name is original name of the user whose attributes should be "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"overridden. The rest of fields correspond to new values. You can omit a "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"value simply by leaving corresponding field empty."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:140
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "ckent:superman::::::"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:143
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ckent@krypton.com::501:501:Superman:/home/earth:/bin/bash:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:149
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>user-export</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:154
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Export all overridden attributes and store them in <emphasis>FILE</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis>. See <emphasis>user-import</emphasis> for data format."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:162
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"<option>group-add</option> <emphasis>NAME</emphasis> <optional><option>-n,--"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"name</option> NAME</optional> <optional><option>-g,--gid</option> GID</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"optional>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:169
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Override attributes of a group. Please be aware that calling this command "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"will replace any previous override for the (NAMEd) group."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:177
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-del</option> <emphasis>NAME</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:182
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Remove group overrides. However be aware that overridden attributes might be "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"returned from memory cache. Please see SSSD option "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<emphasis>memcache_timeout</emphasis> for more details."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:191
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>group-find</option> <optional><option>-d,--domain</option> DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"optional>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-d</option>,<option>--domain</option> <replaceable>DOMAIN</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:196
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"List all groups with set overrides. If <emphasis>DOMAIN</emphasis> "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"parameter is set, only groups from the domain are listed."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:204
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>group-show</option> <emphasis>NAME</emphasis>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:209
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Show group overrides."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:215
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-import</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:220
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Import group overrides from <emphasis>FILE</emphasis>. Data format is "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"similar to standard group file. The format is:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:225
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "original_name:name:gid"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:228
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"where original_name is original name of the group whose attributes should be "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"overridden. The rest of fields correspond to new values. You can omit a "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"value simply by leaving corresponding field empty."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:237
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "admins:administrators:"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:240
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Domain Users:Users:501"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:246
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>group-export</option> <emphasis>FILE</emphasis>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_override.8.xml:251
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Export all overridden attributes and store them in <emphasis>FILE</"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"emphasis>. See <emphasis>group-import</emphasis> for data format."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sss_override.8.xml:261 sssctl.8.xml:50
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "CONFIGURATION OPTIONS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "COMMON OPTIONS"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "OPÇÕES DE CONFIGURAÇÃO"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sss_override.8.xml:263 sssctl.8.xml:52
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Those options are available with all commands."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sss_override.8.xml:268 sssctl.8.xml:57
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#, fuzzy
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#| msgid "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "<option>--debug</option> <replaceable>LEVEL</replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr "<option>--debug-timestamps=</option><replaceable>mode</replaceable>"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:10 sss_useradd.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_useradd"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "create a new user"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_useradd</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_useradd</command> creates a new user account using the values "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"specified on the command line plus the default values from the system."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:43 sss_seed.8.xml:76
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-u</option>,<option>--uid</option> <replaceable>UID</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:48
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Set the UID of the user to the value of <replaceable>UID</replaceable>. If "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"not given, it is chosen automatically."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:55 sss_usermod.8.xml:43 sss_seed.8.xml:100
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-c</option>,<option>--gecos</option> <replaceable>COMMENT</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:60 sss_usermod.8.xml:48 sss_seed.8.xml:105
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Any text string describing the user. Often used as the field for the user's "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"full name."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:67 sss_usermod.8.xml:55 sss_seed.8.xml:112
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-h</option>,<option>--home</option> <replaceable>HOME_DIR</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:72
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The home directory of the user account. The default is to append the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>LOGIN</replaceable> name to <filename>/home</filename> and use "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"that as the home directory. The base that is prepended before "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>LOGIN</replaceable> is tunable with <quote>user_defaults/"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"baseDirectory</quote> setting in sssd.conf."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_useradd.8.xml:82 sss_usermod.8.xml:66 sss_seed.8.xml:124
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-s</option>,<option>--shell</option> <replaceable>SHELL</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:87
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The user's login shell. The default is currently <filename>/bin/bash</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"filename>. The default can be changed with <quote>user_defaults/"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"defaultShell</quote> setting in sssd.conf."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:96
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-G</option>,<option>--groups</option> <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:101
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "A list of existing groups this user is also a member of."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:107
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-m</option>,<option>--create-home</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:111
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Create the user's home directory if it does not exist. The files and "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"directories contained in the skeleton directory (which can be defined with "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the -k option or in the config file) will be copied to the home directory."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:121
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-M</option>,<option>--no-create-home</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:125
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Do not create the user's home directory. Overrides configuration settings."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:132
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-k</option>,<option>--skel</option> <replaceable>SKELDIR</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:137
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The skeleton directory, which contains files and directories to be copied in "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the user's home directory, when the home directory is created by "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_useradd</command>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_useradd.8.xml:143
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"Special files (block devices, character devices, named pipes and unix "
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek"sockets) will not be copied."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:147
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This option is only valid if the <option>-m</option> (or <option>--create-"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"home</option>) option is specified, or creation of home directories is set "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"to TRUE in the configuration."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:156 sss_usermod.8.xml:124
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-Z</option>,<option>--selinux-user</option> "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>SELINUX_USER</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#: sss_useradd.8.xml:161
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The SELinux user for the user's login. If not specified, the system default "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"will be used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:10 sssd-krb5.5.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sssd-krb5"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD Kerberos provider"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:23
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This manual page describes the configuration of the Kerberos 5 "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authentication backend for <citerefentry> <refentrytitle>sssd</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle> <manvolnum>8</manvolnum> </citerefentry>. For a detailed "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"syntax reference, please refer to the <quote>FILE FORMAT</quote> section of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"manvolnum> </citerefentry> manual page."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:36
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The Kerberos 5 authentication backend contains auth and chpass providers. It "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"must be paired with an identity provider in order to function properly (for "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"example, id_provider = ldap). Some information required by the Kerberos 5 "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authentication backend must be provided by the identity provider, such as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"the user's Kerberos Principal Name (UPN). The configuration of the identity "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"provider should have an entry to specify the UPN. Please refer to the man "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"page for the applicable identity provider for details on how to configure "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"this."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:47
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This backend also provides access control based on the .k5login file in the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"home directory of the user. See <citerefentry> <refentrytitle>.k5login</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"refentrytitle><manvolnum>5</manvolnum> </citerefentry> for more details. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please note that an empty .k5login file will deny all access to this user. "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"To activate this feature, use 'access_provider = krb5' in your SSSD "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"configuration."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:55
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"In the case where the UPN is not available in the identity backend, "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sssd</command> will construct a UPN using the format "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>username</replaceable>@<replaceable>krb5_realm</replaceable>."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#: sssd-krb5.5.xml:77
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Specifies the comma-separated list of IP addresses or hostnames of the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Kerberos servers to which SSSD should connect, in the order of preference. "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"For more information on failover and server redundancy, see the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>FAILOVER</quote> section. An optional port number (preceded by a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"colon) may be appended to the addresses or hostnames. If empty, service "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"discovery is enabled; for more information, refer to the <quote>SERVICE "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"DISCOVERY</quote> section."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:106
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The name of the Kerberos realm. This option is required and must be "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"specified."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:113
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "krb5_kpasswd, krb5_backup_kpasswd (string)"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:116
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"If the change password service is not running on the KDC, alternative "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"servers can be defined here. An optional port number (preceded by a colon) "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"may be appended to the addresses or hostnames."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:122
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For more information on failover and server redundancy, see the "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>FAILOVER</quote> section. NOTE: Even if there are no more kpasswd "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"servers to try, the backend is not switched to operate offline if "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"authentication against the KDC is still possible."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:129
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: Use the KDC"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: Usar o KDC"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:135
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_ccachedir (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_ccachedir (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:138
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Directory to store credential caches. All the substitution sequences of "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"krb5_ccname_template can be used here, too, except %d and %P. The directory "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is created as private and owned by the user, with permissions set to 0700."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:145
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: /tmp"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: /tmp."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:151
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_ccname_template (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_ccname_template (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:165 include/override_homedir.xml:11
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%u"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "%u"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:166 include/override_homedir.xml:12
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "login name"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "nome de login"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:169 include/override_homedir.xml:15
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%U"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "%U"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:170
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "login UID"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:173
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "%p"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "%p"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:174
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "principal name"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "nome principal"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:178
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "%r"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "%r"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:179
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "realm name"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "nome de território"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:182
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "%h"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "%h"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:183 sssd-ifp.5.xml:108
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "home directory"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:187 include/override_homedir.xml:19
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%d"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "%d"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:188
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "value of krb5_ccachedir"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:193 include/override_homedir.xml:27
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "%P"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "%P"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:194
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "the process ID of the SSSD client"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:199 include/override_homedir.xml:45
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%%"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "%%"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: sssd-krb5.5.xml:200 include/override_homedir.xml:46
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "a literal '%'"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "um literal '%'"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:154
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"Location of the user's credential cache. Three credential cache types are "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"currently supported: <quote>FILE</quote>, <quote>DIR</quote> and "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"<quote>KEYRING:persistent</quote>. The cache can be specified either as "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"<replaceable>TYPE:RESIDUAL</replaceable>, or as an absolute path, which "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"implies the <quote>FILE</quote> type. In the template, the following "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"sequences are substituted: <placeholder type=\"variablelist\" id=\"0\"/> If "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"the template ends with 'XXXXXX' mkstemp(3) is used to create a unique "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"filename in a safe way."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:208
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"When using KEYRING types, the only supported mechanism is <quote>KEYRING:"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"persistent:%U</quote>, which uses the Linux kernel keyring to store "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"credentials on a per-UID basis. This is also the recommended choice, as it "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"is the most secure and predictable method."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:216
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"The default value for the credential cache name is sourced from the profile "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"stored in the system wide krb5.conf configuration file in the [libdefaults] "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"section. The option name is default_ccache_name. See krb5.conf(5)'s "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"PARAMETER EXPANSION paragraph for additional information on the expansion "
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek"format defined by krb5.conf."
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-krb5.5.xml:225
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"NOTE: Please be aware that libkrb5 ccache expansion template from "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<citerefentry> <refentrytitle>krb5.conf</refentrytitle> <manvolnum>5</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"manvolnum> </citerefentry> uses different expansion sequences than SSSD."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:234
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgid "Default: (from libkrb5)"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:240
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_auth_timeout (integer)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_auth_timeout (integer)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:243
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Timeout in seconds after an online authentication request or change password "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"request is aborted. If possible, the authentication request is continued "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"offline."
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:257
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Verify with the help of krb5_keytab that the TGT obtained has not been "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"spoofed. The keytab is checked for entries sequentially, and the first entry "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"with a matching realm is used for validation. If no entry matches the realm, "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"the last entry in the keytab is used. This process can be used to validate "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"environments using cross-realm trust by placing the appropriate keytab entry "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"as the last entry or the only entry in the keytab file."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:272
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_keytab (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_keytab (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:275
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The location of the keytab to use when validating credentials obtained from "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"KDCs."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:279
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: /etc/krb5.keytab"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: /etc/krb5.keytab"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:285
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_store_password_if_offline (boolean)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_store_password_if_offline (boolean)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:288
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Store the password of the user if the provider is offline and use it to "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"request a TGT when the provider comes online again."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:293
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: this feature is only available on Linux. Passwords stored in this way "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"are kept in plaintext in the kernel keyring and are potentially accessible "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"by the root user (with difficulty)."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:306
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_renewable_lifetime (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_renewable_lifetime (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:309
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"Request a renewable ticket with a total lifetime, given as an integer "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"immediately followed by a time unit:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:314 sssd-krb5.5.xml:348 sssd-krb5.5.xml:385
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>s</emphasis> for seconds"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:317 sssd-krb5.5.xml:351 sssd-krb5.5.xml:388
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>m</emphasis> for minutes"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:320 sssd-krb5.5.xml:354 sssd-krb5.5.xml:391
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>h</emphasis> for hours"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:323 sssd-krb5.5.xml:357 sssd-krb5.5.xml:394
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "<emphasis>d</emphasis> for days."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:326 sssd-krb5.5.xml:397
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If there is no unit given, <emphasis>s</emphasis> is assumed."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:330 sssd-krb5.5.xml:401
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: It is not possible to mix units. To set the renewable lifetime to one "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"and a half hours, use '90m' instead of '1h30m'."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:335
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: not set, i.e. the TGT is not renewable"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Padrão: não definido, ou seja, o TGT não é renovável"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:341
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_lifetime (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_lifetime (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:344
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Request ticket with a lifetime, given as an integer immediately followed by "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"a time unit:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:360
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If there is no unit given <emphasis>s</emphasis> is assumed."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:364
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"NOTE: It is not possible to mix units. To set the lifetime to one and a "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"half hours please use '90m' instead of '1h30m'."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:369
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Default: not set, i.e. the default ticket lifetime configured on the KDC."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:376
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "krb5_renew_interval (string)"
b20208b80e99abb79c00d5ec526caa9465859c52Jakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:379
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The time in seconds between two checks if the TGT should be renewed. TGTs "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"are renewed if about half of their lifetime is exceeded, given as an integer "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"immediately followed by a time unit:"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:406
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "If this option is not set or is 0 the automatic renewal is disabled."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:424
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<emphasis>never</emphasis> use FAST. This is equivalent to not setting this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"option at all."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:428
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<emphasis>try</emphasis> to use FAST. If the server does not support FAST, "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"continue the authentication without it."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:438
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Default: not set, i.e. FAST is not used."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:441
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgid "NOTE: a keytab is required to use FAST."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:453
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "krb5_fast_principal (string)"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "krb5_fast_principal (string)"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:456
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Specifies the server principal to use for FAST."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:465
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgid ""
bdd205037059e56484de3174951b22ff8f0f79f8Stephen Gallagher"Specifies if the host and user principal should be canonicalized. This "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"feature is available with MIT Kerberos 1.7 and later versions."
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallaghermsgstr ""
3a8abe04137d028b8ebd1cb33152aefa55893efbStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: sssd-krb5.5.xml:514
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: false (AD provider: true)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:517
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"The IPA provider will set to option to 'true' if it detects that the server "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"is capable of handling enterprise principals and the option is not set "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"explicitly in the config file."
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozekmsgstr ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><term>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:526
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid "krb5_map_user (string)"
531661c7bb54eb71853977a64cb30f80c20b963eJakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:529
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"The list of mappings is given as a comma-separated list of pairs "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>username:primary</quote> where <quote>username</quote> is a UNIX user "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"name and <quote>primary</quote> is a user part of a kerberos principal. This "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"mapping is used when user is authenticating using <quote>auth_provider = "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5</quote>."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:541
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_realm = REALM\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_map_user = joe:juser,dick:richard\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><variablelist><varlistentry><listitem><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:546
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>joe</quote> and <quote>dick</quote> are UNIX user names and "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>juser</quote> and <quote>richard</quote> are primaries of kerberos "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"principals. For user <quote>joe</quote> resp. <quote>dick</quote> SSSD will "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"try to kinit as <quote>juser@REALM</quote> resp. <quote>richard@REALM</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"quote>."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sssd-krb5.5.xml:65
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"If the auth-module krb5 is used in an SSSD domain, the following options "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"must be used. See the <citerefentry> <refentrytitle>sssd.conf</"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page, section "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"<quote>DOMAIN SECTIONS</quote>, for details on the configuration of an SSSD "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"domain. <placeholder type=\"variablelist\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:572
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The following example assumes that SSSD is correctly configured and FOO is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"one of the domains in the <replaceable>[sssd]</replaceable> section. This "
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozek"example shows only configuration of Kerberos authentication; it does not "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"include any identity provider."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssd-krb5.5.xml:580
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#, no-wrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"[domain/FOO]\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"auth_provider = krb5\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_server = 192.168.1.1\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"krb5_realm = EXAMPLE.COM\n"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupadd.8.xml:10 sss_groupadd.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_groupadd"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupadd.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "create a new group"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupadd.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupadd</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupadd.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupadd</command> creates a new group. These groups are "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"compatible with POSIX groups, with the additional feature that they can "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"contain other groups as members."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_groupadd.8.xml:43 sss_seed.8.xml:88
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<option>-g</option>,<option>--gid</option> <replaceable>GID</replaceable>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupadd.8.xml:48
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Set the GID of the group to the value of <replaceable>GID</replaceable>. If "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"not given, it is chosen automatically."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:10 sss_userdel.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_userdel"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "delete a user account"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_userdel</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_userdel</command> deletes a user identified by login name "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>LOGIN</replaceable> from the system."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:44
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-r</option>,<option>--remove</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:48
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Files in the user's home directory will be removed along with the home "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"directory itself and the user's mail spool. Overrides the configuration."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:56
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-R</option>,<option>--no-remove</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:60
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Files in the user's home directory will NOT be removed along with the home "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"directory itself and the user's mail spool. Overrides the configuration."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:68
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-f</option>,<option>--force</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:72
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"This option forces <command>sss_userdel</command> to remove the user's home "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"directory and mail spool, even if they are not owned by the specified user."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:80
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-k</option>,<option>--kick</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_userdel.8.xml:84
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Before actually deleting the user, terminate all his processes."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupdel.8.xml:10 sss_groupdel.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_groupdel"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sss_groupdel"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupdel.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "delete a group"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "excluir um grupo"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupdel.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupdel</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_groupdel</command> <arg choice='opt'> <replaceable>options</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupdel.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupdel</command> deletes a group identified by its name "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>GROUP</replaceable> from the system."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:10 sss_groupshow.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_groupshow"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sss_groupshow"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "print properties of a group"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupshow</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_groupshow</command> <arg choice='opt'> <replaceable>options</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_groupshow</command> displays information about a group "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"identified by its name <replaceable>GROUP</replaceable>. The information "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"includes the group ID number, members of the group and the parent group."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:43
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-R</option>,<option>--recursive</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-R</option>,<option>--recursive</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_groupshow.8.xml:47
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Also print indirect group members in a tree-like hierarchy. Note that this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"also affects printing parent groups - without <option>R</option>, only the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"direct parent will be printed."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:10 sss_usermod.8.xml:15
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "sss_usermod"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "sss_usermod"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:16
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "modify a user account"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "modificar uma conta de utilizador"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:21
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_usermod</command> <arg choice='opt'> <replaceable>options</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"<command>sss_usermod</command> <arg choice='opt'> <replaceable>options</"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>LOGIN</replaceable></"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"arg>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:32
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<command>sss_usermod</command> modifies the account specified by "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<replaceable>LOGIN</replaceable> to reflect the changes that are specified "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"on the command line."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:60
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The home directory of the user account."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:71
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The user's login shell."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:82
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Append this user to groups specified by the <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> parameter. The <replaceable>GROUPS</replaceable> parameter is "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"a comma separated list of group names."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:96
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Remove this user from groups specified by the <replaceable>GROUPS</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"replaceable> parameter."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:103
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-l</option>,<option>--lock</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-l</option>,<option>--lock</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:107
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Lock the user account. The user won't be able to log in."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
b355dcb54194f498921743ca33304eac35d89718Stephen Gallagher"Bloquear a conta do utilizador. O utilizador não será capaz de efetuar login."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:114
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<option>-u</option>,<option>--unlock</option>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<option>-u</option>,<option>--unlock</option>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:118
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Unlock the user account."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Desbloquear a conta de utilizador."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: sss_usermod.8.xml:129
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The SELinux user for the user's login."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:135
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--addattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:140
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Add an attribute/value pair. The format is attrname=value."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:147
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--setattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:152
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"Set an attribute to a name/value pair. The format is attrname=value. For "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"multi-valued attributes, the command replaces the values already present"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:160
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "<option>--delattr</option> <replaceable>ATTR_NAME_VAL</replaceable>"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: sss_usermod.8.xml:165
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Delete an attribute/value pair. The format is attrname=value."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:10 sss_cache.8.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_cache"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "perform cache cleanup"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_cache</command> <arg choice='opt'> <replaceable>options</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable> </arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_cache.8.xml:31
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_cache</command> invalidates records in SSSD cache. Invalidated "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"records are forced to be reloaded from server as soon as related SSSD "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"backend is online. Options that invalidate a single object only accept a "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"single provided argument."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:43
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgid "<option>-E</option>,<option>--everything</option>"
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:47
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "Invalidate all cached entries."
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozekmsgstr ""
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek
d6d50c17e94dc0d3000345e8a933311c14bbb828Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:53
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-u</option>,<option>--user</option> <replaceable>login</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:58
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific user."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:64
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-U</option>,<option>--users</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:68
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all user records. This option overrides invalidation of specific "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"user if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:75
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-g</option>,<option>--group</option> <replaceable>group</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:80
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific group."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:86
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-G</option>,<option>--groups</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:90
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all group records. This option overrides invalidation of specific "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"group if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:97
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-n</option>,<option>--netgroup</option> <replaceable>netgroup</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:102
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Invalidate specific netgroup."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:108
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<option>-N</option>,<option>--netgroups</option>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:112
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Invalidate all netgroup records. This option overrides invalidation of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"specific netgroup if it was also set."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:119
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-s</option>,<option>--service</option> <replaceable>service</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:124
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Invalidate specific service."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:130
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>-S</option>,<option>--services</option>"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:134
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Invalidate all service records. This option overrides invalidation of "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"specific service if it was also set."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:141
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<option>-a</option>,<option>--autofs-map</option> <replaceable>autofs-map</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:146
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Invalidate specific autofs maps."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:152
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "<option>-A</option>,<option>--autofs-maps</option>"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:156
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Invalidate all autofs maps. This option overrides invalidation of specific "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"map if it was also set."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:163
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<option>-h</option>,<option>--ssh-host</option> <replaceable>hostname</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"replaceable>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:168
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Invalidate SSH public keys of a specific host."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:174
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "<option>-H</option>,<option>--ssh-hosts</option>"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:178
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Invalidate SSH public keys of all hosts. This option overrides invalidation "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"of SSH public keys of specific host if it was also set."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:186
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "<option>-f</option>,<option>--file</option> <replaceable>FILE</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| "replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-r</option>,<option>--sudo-rule</option> <replaceable>rule</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-f</option>,<option>--file</option> <replaceable>FILE</replaceable>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:191
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "Invalidate particular sudo rule."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:197
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "<option>-R</option>,<option>--recursive</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "<option>-R</option>,<option>--sudo-rules</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "<option>-R</option>,<option>--recursive</option>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:201
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Invalidate all cached sudo rules. This option overrides invalidation of "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"specific sudo rule if it was also set."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:209
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<option>-d</option>,<option>--domain</option> <replaceable>domain</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"replaceable>"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sss_cache.8.xml:214
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Restrict invalidation process only to a particular domain."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:10 sss_debuglevel.8.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_debuglevel"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "change debug level while SSSD is running"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_debuglevel</command> <arg choice='opt'> <replaceable>options</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable> </arg> <arg choice='plain'><replaceable>NEW_DEBUG_LEVEL</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:32
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_debuglevel</command> changes debug level of SSSD monitor and "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"providers to <replaceable>NEW_DEBUG_LEVEL</replaceable> while SSSD is "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"running."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_debuglevel.8.xml:59
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "<replaceable>NEW_DEBUG_LEVEL</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:10 sss_seed.8.xml:15
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "sss_seed"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "seed the SSSD cache with a user"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:21
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<command>sss_seed</command> <arg choice='opt'> <replaceable>options</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable> </arg> <arg choice='plain'>-D <replaceable>DOMAIN</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable></arg> <arg choice='plain'>-n <replaceable>USER</replaceable></"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"arg>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:33
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<command>sss_seed</command> seeds the SSSD cache with a user entry and "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"temporary password. If a user entry is already present in the SSSD cache "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"then the entry is updated with the temporary password."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:46
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-D</option>,<option>--domain</option> <replaceable>DOMAIN</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:51
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Provide the name of the domain in which the user is a member of. The domain "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"is also used to retrieve user information. The domain must be configured in "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"sssd.conf. The <replaceable>DOMAIN</replaceable> option must be provided. "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Information retrieved from the domain overrides what is provided in the "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"options."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:63
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-n</option>,<option>--username</option> <replaceable>USER</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:68
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"The username of the entry to be created or modified in the cache. The "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<replaceable>USER</replaceable> option must be provided."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:81
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the UID of the user to <replaceable>UID</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:93
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the GID of the user to <replaceable>GID</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:117
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Set the home directory of the user to <replaceable>HOME_DIR</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:129
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid "Set the login shell of the user to <replaceable>SHELL</replaceable>."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:140
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Interactive mode for entering user information. This option will only prompt "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"for information not provided in the options or retrieved from the domain."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:148
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<option>-p</option>,<option>--password-file</option> <replaceable>PASS_FILE</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"replaceable>"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: sss_seed.8.xml:153
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"Specify file to read user's password from. (if not specified password is "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"prompted for)"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: sss_seed.8.xml:165
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"The length of the password (or the size of file specified with -p or --"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"password-file option) must be less than or equal to PASS_MAX bytes (64 bytes "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"on systems with no globally-defined PASS_MAX value)."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:10 sssd-ifp.5.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "sssd-ifp"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:17
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "SSSD InfoPipe responder"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:23
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"This manual page describes the configuration of the InfoPipe responder for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:36
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The InfoPipe responder provides a public D-Bus interface accessible over the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"system bus. The interface allows the user to query information about remote "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"users and groups over the system bus."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:46
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "These options can be used to configure the InfoPipe responder."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:53
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Specifies the comma-separated list of UID values or user names that are "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"allowed to access the InfoPipe responder. User names are resolved to UIDs at "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"startup."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:59
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Default: 0 (only the root user is allowed to access the InfoPipe responder)"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:63
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that although the UID 0 is used as the default it will be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"overwritten with this option. If you still want to allow the root user to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"access the InfoPipe responder, which would be the typical case, you have to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"add 0 to the list of allowed UIDs as well."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:77
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Specifies the comma-separated list of white or blacklisted attributes."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:91
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "name"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:92
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user's login name"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:95
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "uidNumber"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:96
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user ID"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:99
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "gidNumber"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:100
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "primary group ID"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:103
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "gecos"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:104
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user information, typically full name"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:107
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "homeDirectory"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:111
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "loginShell"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:112
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "user shell"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:81
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"By default, the InfoPipe responder only allows the default set of POSIX "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"attributes to be requested. This set is the same as returned by "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>getpwnam</refentrytitle> <manvolnum>3</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry> and includes: <placeholder type=\"variablelist\" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:125
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#, no-wrap
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"user_attributes = +telephoneNumber, -loginShell\n"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek" "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:117
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"It is possible to add another attribute to this set by using <quote>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"+attr_name</quote> or explicitly remove an attribute using <quote>-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"attr_name</quote>. For example, to allow <quote>telephoneNumber</quote> but "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"deny <quote>loginShell</quote>, you would use the following configuration: "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: sssd-ifp.5.xml:129
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Default: not set. Only the default set of POSIX attributes is allowed."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ifp.5.xml:139
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"Specifies an upper limit on the number of entries that are downloaded during "
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek"a wildcard lookup that overrides caller-supplied limit."
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek#: sssd-ifp.5.xml:144
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgid "Default: 0 (let the caller set an upper limit)"
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozekmsgstr ""
261cdde02b40aa8dabb3d69e43586a5a220647e9Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refentryinfo>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:8
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<productname>sss rpc.idmapd plugin</productname> <author> <firstname>Noam</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"firstname> <surname>Meltzer</surname> <affiliation> <orgname>Primary Data "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Inc.</orgname> </affiliation> <contrib>Developer (2013-2014)</contrib> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"author> <author> <firstname>Noam</firstname> <surname>Meltzer</surname> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<contrib>Developer (2014-)</contrib> <email>tsnoam@gmail.com</email> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"author>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:26 sss_rpcidmapd.5.xml:32
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sss_rpcidmapd"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:33
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "sss plugin configuration directives for rpc.idmapd"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:37
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "CONFIGURATION FILE"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:39
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"rpc.idmapd configuration file is usually found at <emphasis>/etc/idmapd."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"conf</emphasis>. See <citerefentry> <refentrytitle>idmapd.conf</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> for more information."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:49
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SSS CONFIGURATION EXTENSION"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:51
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Enable SSS plugin"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:53
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"In section <quote>[Translation]</quote>, modify/set <quote>Method</quote> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"attribute to contain <emphasis>sss</emphasis>."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:59
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "[sss] config section"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:61
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"In order to change the default of one of the configuration attributes of the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<emphasis>sss</emphasis> plugin listed below you will need to create a "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"config section for it, named <quote>[sss]</quote>."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:67
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Configuration attributes"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><term>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:69
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "memcache (bool)"
481ec0e1eb0058195732cb320845b41f6f4d43ebJakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><refsect2><variablelist><varlistentry><listitem><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:72
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "Indicates whether or not to use memcache optimisation technique."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:85
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SSSD INTEGRATION"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:87
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The sss plugin requires the <emphasis>NSS Responder</emphasis> to be enabled "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"in sssd."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:91
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The attribute <quote>use_fully_qualified_names</quote> must be enabled on "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"all domains (NFSv4 clients expect a fully qualified name to be sent on the "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"wire)."
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:103
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#, no-wrap
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[General]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Verbosity = 2\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"# domain must be synced between NFSv4 server and clients\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"# Solaris/Illumos/AIX use \"localdomain\" as default!\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Domain = default\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[Mapping]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Nobody-User = nfsnobody\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Nobody-Group = nfsnobody\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"[Translation]\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"Method = sss\n"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:100
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"The following example shows a minimal idmapd.conf which makes use of the sss "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"plugin. <placeholder type=\"programlisting\" id=\"0\"/>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <refsect1><title>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:120 include/seealso.xml:2
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid "SEE ALSO"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr "VER TAMBÉM"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek#: sss_rpcidmapd.5.xml:122
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgid ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>idmapd.conf</refentrytitle> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<manvolnum>5</manvolnum> </citerefentry>"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozekmsgstr ""
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:10 sss_ssh_authorizedkeys.1.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_ssh_authorizedkeys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refmeta><manvolnum>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:11 sss_ssh_knownhostsproxy.1.xml:11
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "1"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "get OpenSSH authorized keys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_authorizedkeys</command> <arg choice='opt'> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>options</replaceable> </arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='plain'><replaceable>USER</replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:32
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_authorizedkeys</command> acquires SSH public keys for user "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>USER</replaceable> and outputs them in OpenSSH authorized_keys "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"format (see the <quote>AUTHORIZED_KEYS FILE FORMAT</quote> section of "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> for more information)."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_authorizedkeys.1.xml:41
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> can be configured to use <command>sss_ssh_authorizedkeys</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"command> for public key user authentication if it is compiled with support "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"for <quote>AuthorizedKeysCommand</quote> option. Please refer to the "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<citerefentry> <refentrytitle>sshd_config</refentrytitle> <manvolnum>5</"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"manvolnum></citerefentry> man page for more details about this option."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:59
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#, no-wrap
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys\n"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek" AuthorizedKeysCommandUser nobody\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:52
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"If <quote>AuthorizedKeysCommand</quote> is supported, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</manvolnum></"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"citerefentry> can be configured to use it by putting the following "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"directives in <citerefentry> <refentrytitle>sshd_config</refentrytitle> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<manvolnum>5</manvolnum></citerefentry>: <placeholder type=\"programlisting"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:75
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Search for user public keys in SSSD domain <replaceable>DOMAIN</replaceable>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:84 sss_ssh_knownhostsproxy.1.xml:92
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "EXIT STATUS"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: sss_ssh_authorizedkeys.1.xml:86 sss_ssh_knownhostsproxy.1.xml:94
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"In case of success, an exit value of 0 is returned. Otherwise, 1 is returned."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refname>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:10 sss_ssh_knownhostsproxy.1.xml:15
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "sss_ssh_knownhostsproxy"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refnamediv><refpurpose>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:16
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "get OpenSSH host keys"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:21
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_knownhostsproxy</command> <arg choice='opt'> "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<replaceable>options</replaceable> </arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='plain'><replaceable>HOST</replaceable></arg> <arg "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"choice='opt'><replaceable>PROXY_COMMAND</replaceable></arg>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:33
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<command>sss_ssh_knownhostsproxy</command> acquires SSH host public keys for "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"host <replaceable>HOST</replaceable>, stores them in a custom OpenSSH "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"known_hosts file (see the <quote>SSH_KNOWN_HOSTS FILE FORMAT</quote> section "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"of <citerefentry><refentrytitle>sshd</refentrytitle> <manvolnum>8</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"manvolnum></citerefentry> for more information) <filename>/var/lib/sss/"
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"pubconf/known_hosts</filename> and establishes the connection to the host."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:43
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"If <replaceable>PROXY_COMMAND</replaceable> is specified, it is used to "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"create the connection to the host instead of opening a socket."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para><programlisting>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:55
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#, no-wrap
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"ProxyCommand /usr/bin/sss_ssh_knownhostsproxy -p %p %h\n"
dd3ba5c5b7d2a9d109963ae9e6c94fff34872221Stephen Gallagher"GlobalKnownHostsFile /var/lib/sss/pubconf/known_hosts\n"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><para>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: sss_ssh_knownhostsproxy.1.xml:48
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> can be configured to use <command>sss_ssh_knownhostsproxy</"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"command> for host key authentication by using the following directives for "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<citerefentry><refentrytitle>ssh</refentrytitle> <manvolnum>1</manvolnum></"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"citerefentry> configuration: <placeholder type=\"programlisting\" id=\"0\"/>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:66
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<option>-p</option>,<option>--port</option> <replaceable>PORT</replaceable>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:71
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Use port <replaceable>PORT</replaceable> to connect to the host. By "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"default, port 22 is used."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
ea929f1b022fc2cb77dec89b0e12accef983ec85Jakub Hrozek#: sss_ssh_knownhostsproxy.1.xml:83
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"Search for host public keys in SSSD domain <replaceable>DOMAIN</replaceable>."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:10 idmap_sss.8.xml:15
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, fuzzy
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#| msgid "pam_sss"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "idmap_sss"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr "pam_sss"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:16
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "SSSSD's idmap_sss Backend for Winbind"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:22
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"The idmap_sss module provides a way to call SSSD to map UIDs/GIDs and SIDs. "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"No database is required in this case as the mapping is done by SSSD."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:29
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, fuzzy
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#| msgid "OPTIONS"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "IDMAP OPTIONS"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr "Opções"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:33
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "range = low - high"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:35
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"Defines the available matching uid and gid range for which the backend is "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"authoritative."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:43
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, fuzzy
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#| msgid "EXAMPLE"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid "EXAMPLES"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr "EXEMPLO"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:45
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"This example shows how to configure idmap_sss as the default mapping module."
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#. type: Content of: <reference><refentry><refsect1><programlisting>
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#: idmap_sss.8.xml:50
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek#, no-wrap
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"[global]\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"security = domain\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"workgroup = MAIN\n"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek"\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"idmap config * : backend = sss\n"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"idmap config * : range = 200000-2147483647\n"
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek" "
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozekmsgstr ""
a86d6cd05e3f823214587475b83d907f394c035eJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:10 sssctl.8.xml:15
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "sssctl"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:16
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid "SSSD control and status utility"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsynopsisdiv><cmdsynopsis>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:21
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#, fuzzy
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| msgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "<command>sss_groupdel</command> <arg choice='opt'> <replaceable>options</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#| "arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<command>sssctl</command> <arg choice='plain'><replaceable>COMMAND</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"replaceable></arg> <arg choice='opt'> <replaceable>options</replaceable> </"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"<command>sss_groupdel</command> <arg choice='opt'> <replaceable>options</"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"replaceable> </arg> <arg choice='plain'><replaceable>GROUP</replaceable></"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"arg>"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#: sssctl.8.xml:32
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"<command>sssctl</command> provides a simple and unified way to obtain "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"information about SSSD status, such as active server, auto-discovered "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"servers, domains and cached objects. In addition, it can manage SSSD data "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"files for troubleshooting in such a way that is safe to manipulate while "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"SSSD is running."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek#: sssctl.8.xml:43
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgid ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"To list all available commands run <command>sssctl</command> without any "
ad805face83ba7d67b1cf2067a1982c7e63d1060Jakub Hrozek"parameters. To print help for selected command run <command>sssctl COMMAND --"
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek"help</command>."
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozekmsgstr ""
d25fa6f2608d5fe0617ada47f9d426f45deb96ffJakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refname>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:10 sssd-secrets.5.xml:16
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "sssd-simple"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "sssd-secrets"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "sssd-simple"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refnamediv><refpurpose>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:17
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "SSSD Secrets responder"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:23
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"This manual page describes the configuration of the Secrets responder for "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle> <manvolnum>8</manvolnum> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"</citerefentry>. For a detailed syntax reference, refer to the <quote>FILE "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"FORMAT</quote> section of the <citerefentry> <refentrytitle>sssd.conf</"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"refentrytitle> <manvolnum>5</manvolnum> </citerefentry> manual page."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:36
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Many system and user applications need to store private information such as "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"passwords or service keys and have no good way to properly deal with them. "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The simple approach is to embed these <quote>secrets</quote> into "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"configuration files potentially ending up exposing sensitive key material to "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"backups, config management system and in general making it harder to secure "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"data."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:45
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The <ulink url=\"https://github.com/latchset/custodia\">custodia</ulink> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"project was born to deal with this problem in cloud like environments, but "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"we found the idea compelling even at a single system level. As a security "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"service, SSSD is ideal to host this capability while offering the same API "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"via a Unix Socket. This will make it possible to use local calls and have "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"them transparently routed to a local or a remote key management store like "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"IPA Vault for storage, escrow and recovery."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:55
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The secrets are simple key-value pairs. Each user's secrets are namespaced "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"using their user ID, which means the secrets will never collide between "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"users. Secrets can be stored inside <quote>containers</quote> which can be "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"nested."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:63
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "USING THE SECRETS RESPONDER"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:65
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The UNIX socket the SSSD responder listens on is located at <filename>/var/"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"run/secrets.socket</filename>."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:84
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"systemctl start sssd-secrets.socket\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"systemctl enable sssd-secrets.socket\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"systemctl enable sssd-secrets.service\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:69
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The secrets responder is socket-activated by <citerefentry> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<refentrytitle>systemd</refentrytitle> <manvolnum>1</manvolnum> </"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"citerefentry>. Unlike other SSSD responders, it cannot be started by adding "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"the <quote>secrets</quote> string to the <quote>service</quote> directive. "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The systemd socket unit is called <quote>sssd-secrets.socket</quote> and the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"corresponding service file is called <quote>sssd-secrets.service</quote>. In "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"order for the service to be socket-activated, make sure the socket is "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"enabled and active and the service is enabled: <placeholder type="
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\"programlisting\" id=\"0\"/> Please note your distribution may already "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"configure the units for you."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:96
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The generic SSSD responder options such as <quote>debug_level</quote> or "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<quote>fd_limit</quote> are accepted by the secrets responder. Please refer "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"to the <citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"manvolnum> </citerefentry> manual page for a complete list. In addition, "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"there are some secrets-specific options as well."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:107
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "id_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "id_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:120
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "local"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:123
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The secrets are stored in a local database, encrypted at rest with a master "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"key. The local provider does not have any additional config options at the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"moment."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:131
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "proxy"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:134
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The secrets responder forwards the requests to a Custodia server. The proxy "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"provider supports several additional options (see below)."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:110
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"This option specifies where should the secrets be stored. The secrets "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"responder can configure a per-user subsections that define which provider "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"store the secrets for this particular user. The per-user subsections should "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"contain all options for that user's provider. If a per-user section does not "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"exist, the global settings from the secret responder's section are used. "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The following providers are supported: <placeholder type=\"variablelist\" id="
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:143
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "Default: cn"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: local"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "Padrão: NC"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:148
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "reconnection_retries (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "containers_nest_level (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "reconnection_retries (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:151
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "This option specifies the maximum allowed number of nested containers."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:155
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "Default: 3"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: 4"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "Padrão: 3"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:160
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "timeout (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "max_secrets (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "timeout (integer)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:163
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "This option specifies the maximum number of secrets that can be stored."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:167
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "Default: 10"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Default: 1024"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "Padrão: 10"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:173
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The following options are only applicable for configurations that use the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<quote>proxy</quote> provider."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:178
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "proxy_lib_name (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "proxy_url (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "proxy_lib_name (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:181
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The URL the Custodia server is listening on. At the moment, http and https "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"protocols are supported."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:188
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "ldap[s]://&lt;host&gt;[:port]"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "http[s]://&lt;host&gt;[:port]"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "ldap[s]://&lt;host&gt;[:port]"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:191
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Example: http://localhost:8080"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:196
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "auth_type (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:199
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The method to use when authenticating to a Custodia server. The following "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"authentication methods are supported:"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:204
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "basic_auth"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:207
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Authenticate with a username and a password as set in the <quote>username</"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"quote> and <quote>password</quote> options."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:214
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "header"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:217
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Authenticate with HTTP header value as defined in the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<quote>auth_header_name</quote> and <quote>auth_header_value</quote> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"configuration options."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:228
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "auth_header_name (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:231
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"If set, the secrets responder would put a header with this name into the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"HTTP request with the value defined in the <quote>auth_header_value</quote> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"configuration option."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:236
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Example: MYSECRETNAME"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:241
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "auth_header_value (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "auth_provider (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:244
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The value sssd-secrets would use for the <quote>auth_header_name</quote>."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:248
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "Examples:"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Example: mysecret"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "Exemplos:"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:253
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "override_homedir (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "forward_headers (list of strings)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "override_homedir (string)"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:256
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The list of HTTP headers to forward to the Custodia server together with the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"request."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:267
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "USING THE REST API"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:269
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"This section lists the available commands and includes examples using the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<citerefentry> <refentrytitle>curl</refentrytitle> <manvolnum>1</manvolnum> "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"</citerefentry> utility. All requests towards the proxy provider must set "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"the Content Type header to <quote>application/json</quote>. In addition, the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"local provider also supports Content Type set to <quote>application/octet-"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"stream</quote>. Secrets stored with requests that set the Content Type "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"header to <quote>application/octet-stream</quote> are base64-encoded when "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"stored and decoded when retrieved, so it's not possible to store a secret "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"with one Content Type and retrieve with another. The secret URI must begin "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"with <filename>/secrets/</filename>."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:286
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Listing secrets"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:289
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"To list the available secrets, send a HTTP GET request with a trailing slash "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"appended to the container path."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:295
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/json\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XGET http://localhost/secrets/\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:303
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Retrieving a secret"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:306
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"To read a value of a single secret, send a HTTP GET request without a "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"trailing slash. The last portion of the URI is the name of the secret."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:313
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/json\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XGET http://localhost/secrets/foo\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:318
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/octet-stream\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XGET http://localhost/secrets/bar\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:311
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "<placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Examples: <placeholder type=\"programlisting\" id=\"0\"/> <placeholder type="
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\"programlisting\" id=\"1\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "<placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:326
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Setting a secret"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:329
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"To set a secret using the <quote>application/json</quote> type, send a HTTP "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"PUT request with a JSON payload that includes type and value. The type "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"should be set to \"simple\" and the value should be set to the secret value. "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"If a secret with that name already exists, the response is a 409 HTTP error."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:337
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The <quote>application/json</quote> type just sends the secret as the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"message payload."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:346
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/json\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XPUT http://localhost/secrets/foo \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -d'{\"type\":\"simple\",\"value\":\"foosecret\"}'\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:352
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/octet-stream\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XPUT http://localhost/secrets/bar \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -d'barsecret'\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:341
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The following example sets a secret named 'foo' to a value of 'foosecret' "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"and a secret named 'bar' to a value of 'barsecret' using a different Content "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Type. <placeholder type=\"programlisting\" id=\"0\"/> <placeholder type="
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\"programlisting\" id=\"1\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:361
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Creating a container"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:364
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Containers provide an additional namespace for this user's secrets. To "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"create a container, send a HTTP POST request, whose URI ends with the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"container name. Please note the URI must end with a trailing slash."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:374
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/json\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XPOST http://localhost/secrets/mycontainer/\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:371
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The following example creates a container named 'mycontainer': <placeholder "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:383
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"http://localhost/secrets/mycontainer/mysecret\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:380
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"To manipulate secrets under this container, just nest the secrets underneath "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"the container path: <placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><term>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:389
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "Deleting a secret or a container"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:392
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"To delete a secret or a container, send a HTTP DELETE request with a path to "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"the secret or the container."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:398
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"curl -H \"Content-Type: application/json\" \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" --unix-socket /var/run/secrets.socket \\\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" -XDELETE http://localhost/secrets/foo\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><variablelist><varlistentry><listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:396
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, fuzzy
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#| msgid "<placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"The following example deletes a secret named 'foo'. <placeholder type="
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr "<placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><title>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:408
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid "EXAMPLE CUSTODIA AND PROXY PROVIDER CONFIGURATION"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:410
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"For testing the proxy provider, you need to set up a Custodia server to "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"proxy requests to. Please always consult the Custodia documentation, the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"configuration directives might change with different Custodia versions."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:421
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[global]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"server_version = \"Secret/0.0.7\"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"server_url = http://localhost:8080/\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"auditlog = /var/log/custodia.log\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"debug = True\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[store:simple]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"handler = custodia.store.sqlite.SqliteStore\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"dburi = /var/lib/custodia.db\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"table = secrets\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[auth:header]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"handler = custodia.httpd.authenticators.SimpleHeaderAuth\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"header = MYSECRETNAME\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"value = mysecretkey\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[authz:paths]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"handler = custodia.httpd.authorizers.SimplePathAuthz\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"paths = /secrets\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[/]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"handler = custodia.root.Root\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"store = simple\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:415
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"This configuration will set up a Custodia server listening on http://"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"localhost:8080, allowing anyone with header named MYSECRETNAME set to "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"mysecretkey to communicate with the Custodia server. Place the contents "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"into a file (for example, <replaceable>custodia.conf</replaceable>): "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"<placeholder type=\"programlisting\" id=\"0\"/>"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:447
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Then run the <replaceable>custodia</replaceable> command, pointing it at the "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"config file as a command line argument."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:451
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"Please note that currently it's not possible to proxy all requests globally "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"to a Custodia instance. Instead, per-user subsections for user IDs that "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"should proxy requests to Custodia must be defined. The following example "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"illustrates a configuration, where the user with UID 123 would proxy their "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"requests to Custodia, but all other user's requests would be handled by a "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"local provider."
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#. type: Content of: <reference><refentry><refsect1><programlisting>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: sssd-secrets.5.xml:459
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#, no-wrap
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgid ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[secrets]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"[secrets/users/123]\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"provider = proxy\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"proxy_url = http://localhost:8080/secrets/\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"auth_type = header\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"auth_header_name = MYSECRETNAME\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"auth_header_value = mysecretkey\n"
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek" "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozekmsgstr ""
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:2
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "SERVICE DISCOVERY"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "DESCOBERTA DE SERVIÇOS"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:4
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The service discovery feature allows back ends to automatically find the "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"appropriate servers to connect to using a special DNS query. This feature is "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"not supported for backup servers."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/service_discovery.xml:9 include/ldap_id_mapping.xml:99
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Configuration"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Configuração"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:11
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If no servers are specified, the back end automatically uses service "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"discovery to try to find a server. Optionally, the user may choose to use "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"both fixed server addresses and service discovery by inserting a special "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"keyword, <quote>_srv_</quote>, in the list of servers. The order of "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"preference is maintained. This feature is useful if, for example, the user "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"prefers to use service discovery whenever possible, and fall back to a "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"specific server when no servers can be discovered using DNS."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:23
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The domain name"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "O nome de domínio"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:25
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Please refer to the <quote>dns_discovery_domain</quote> parameter in the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"<citerefentry> <refentrytitle>sssd.conf</refentrytitle> <manvolnum>5</"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"manvolnum> </citerefentry> manual page for more details."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:35
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The protocol"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "O protocolo"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:37
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The queries usually specify _tcp as the protocol. Exceptions are documented "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"in respective option description."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:42
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "See Also"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Ver também"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/service_discovery.xml:44
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"For more information on the service discovery mechanism, refer to RFC 2782."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: outside any tag (error?)
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/upstream.xml:1
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "<placeholder type=\"refentryinfo\" id=\"0\"/>"
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "<placeholder type=\"refentryinfo\" id=\"0\"/>"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/failover.xml:2
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "FAILOVER"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/failover.xml:4
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The failover feature allows back ends to automatically switch to a different "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"server if the current server fails."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/failover.xml:8
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Failover Syntax"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/failover.xml:10
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The list of servers is given as a comma-separated list; any number of spaces "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"is allowed around the comma. The servers are listed in order of preference. "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The list can contain any number of servers."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:16
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgid ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"For each failover-enabled config option, two variants exist: "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<emphasis>primary</emphasis> and <emphasis>backup</emphasis>. The idea is "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"that servers in the primary list are preferred and backup servers are only "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"searched if no primary servers can be reached. If a backup server is "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"selected, a timeout of 31 seconds is set. After this timeout SSSD will "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"periodically try to reconnect to one of the primary servers. If it succeeds, "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"it will replace the current active (backup) server."
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><title>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:27
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "The Failover Mechanism"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:29
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"The failover mechanism distinguishes between a machine and a service. The "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"back end first tries to resolve the hostname of a given machine; if this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"resolution attempt fails, the machine is considered offline. No further "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"attempts are made to connect to this machine for any other service. If the "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"resolution attempt succeeds, the back end tries to connect to a service on "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"this machine. If the service connection attempt fails, then only this "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"particular service is considered offline and the back end automatically "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"switches over to the next service. The machine is still considered online "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"and might still be tried for another service."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:42
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"Further connection attempts are made to machines or services marked as "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"offline after a specified period of time; this is currently hard coded to 30 "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"seconds."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <refsect1><refsect2><para>
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek#: include/failover.xml:47
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"If there are no more machines to try, the back end as a whole switches to "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher"offline mode, and then attempts to reconnect every 30 seconds."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:2
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ID MAPPING"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:4
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The ID-mapping feature allows SSSD to act as a client of Active Directory "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"without requiring administrators to extend user attributes to support POSIX "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"attributes for user and group identifiers."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/ldap_id_mapping.xml:9
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: When ID-mapping is enabled, the uidNumber and gidNumber attributes are "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ignored. This is to avoid the possibility of conflicts between automatically-"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"assigned and manually-assigned values. If you need to use manually-assigned "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"values, ALL values must be manually-assigned."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:16
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Please note that changing the ID mapping related configuration options will "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"cause user and group IDs to change. At the moment, SSSD does not support "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"changing IDs, so the SSSD database must be removed. Because cached passwords "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"are also stored in the database, removing the database should only be "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"performed while the authentication servers are reachable, otherwise users "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"might get locked out. In order to cache the password, an authentication must "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"be performed. It is not sufficient to use <citerefentry> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<refentrytitle>sss_cache</refentrytitle> <manvolnum>8</manvolnum> </"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"citerefentry> to remove the database, rather the process consists of:"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:33
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Making sure the remote servers are reachable"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:38
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Stopping the SSSD service"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:43
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Removing the database"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para><itemizedlist><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:48
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Starting the SSSD service"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:52
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Moreover, as the change of IDs might necessitate the adjustment of other "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"system properties such as file and directory ownership, it's advisable to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"plan ahead and test the ID mapping configuration thoroughly."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:59
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Mapping Algorithm"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:61
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory provides an objectSID for every user and group object in "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"the directory. This objectSID can be broken up into components that "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"represent the Active Directory domain identity and the relative identifier "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"(RID) of the user or group object."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:67
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The SSSD ID-mapping algorithm takes a range of available UIDs and divides it "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"into equally-sized component sections - called \"slices\"-. Each slice "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"represents the space available to an Active Directory domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:73
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When a user or group entry for a particular domain is encountered for the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"first time, the SSSD allocates one of the available slices for that domain. "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"In order to make this slice-assignment repeatable on different client "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"machines, we select the slice based on the following algorithm:"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:80
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The SID string is passed through the murmurhash3 algorithm to convert it to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"a 32-bit hashed value. We then take the modulus of this value with the total "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"number of available slices to pick the slice."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:86
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: It is possible to encounter collisions in the hash and subsequent "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"modulus. In these situations, we will select the next available slice, but "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"it may not be possible to reproduce the same exact set of slices on other "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"machines (since the order that they are encountered will determine their "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"slice). In this situation, it is recommended to either switch to using "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"explicit POSIX attributes in Active Directory (disabling ID-mapping) or "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"configure a default domain to guarantee that at least one is always "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"consistent. See <quote>Configuration</quote> for details."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:101
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Minimum configuration (in the <quote>[domain/DOMAINNAME]</quote> section):"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para><programlisting>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:106
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#, no-wrap
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_id_mapping = True\n"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"ldap_schema = ad\n"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:111
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The default configuration results in configuring 10,000 slices, each capable "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"of holding up to 200,000 IDs, starting from 200,000 and going up to "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"2,000,200,000. This should be sufficient for most deployments."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><title>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:117
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Advanced Configuration"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:120
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_min (integer)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:123
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the lower bound of the range of POSIX IDs to use for mapping "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory user and group SIDs."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:127
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"NOTE: This option is different from <quote>min_id</quote> in that "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<quote>min_id</quote> acts to filter the output of requests to this domain, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"whereas this option controls the range of ID assignment. This is a subtle "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"distinction, but the good general advice would be to have <quote>min_id</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> be less-than or equal to <quote>ldap_idmap_range_min</quote>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:137 include/ldap_id_mapping.xml:191
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "Default: 200000"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:142
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_max (integer)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:145
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the upper bound of the range of POSIX IDs to use for mapping "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Active Directory user and group SIDs."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:149
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"NOTE: This option is different from <quote>max_id</quote> in that "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"<quote>max_id</quote> acts to filter the output of requests to this domain, "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"whereas this option controls the range of ID assignment. This is a subtle "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"distinction, but the good general advice would be to have <quote>max_id</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> be greater-than or equal to <quote>ldap_idmap_range_max</quote>"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:159
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "Default: 2000200000"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:164
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_range_size (integer)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:167
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specifies the number of IDs available for each slice. If the range size "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"does not divide evenly into the min and max values, it will create as many "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"complete slices as it can."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:173
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"NOTE: The value of this option must be at least as large as the highest user "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"RID planned for use on the Active Directory server. User lookups and login "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"will fail for any user whose RID is greater than this value."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_id_mapping.xml:179
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"For example, if your most recently-added Active Directory user has "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"objectSid=S-1-5-21-2153326666-2176343378-3404031434-1107, "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"<quote>ldap_idmap_range_size</quote> must be at least 1108 as range size is "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"equal to maximal SID minus minimal SID plus one (e.g. 1108 = 1107 - 0 + 1)."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:186
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"It is important to plan ahead for future expansion, as changing this value "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"will result in changing all of the ID mappings on the system, leading to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"users with different local IDs than they previously had."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:196
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_default_domain_sid (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:199
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Specify the domain SID of the default domain. This will guarantee that this "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"domain will always be assigned to slice zero in the ID map, bypassing the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"murmurhash algorithm described above."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:210
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_default_domain (string)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:213
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "Specify the name of the default domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:221
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "ldap_idmap_autorid_compat (boolean)"
486237ee009f1d84fc4c85665dce80ade76f7079Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:224
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"Changes the behavior of the ID-mapping algorithm to behave more similarly to "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"winbind's <quote>idmap_autorid</quote> algorithm."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:229
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"When this option is configured, domains will be allocated starting with "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"slice zero and increasing monatomically with each additional domain."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:234
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"NOTE: This algorithm is non-deterministic (it depends on the order that "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"users and groups are requested). If this mode is required for compatibility "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"with machines running winbind, it is recommended to also use the "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<quote>ldap_idmap_default_domain_sid</quote> option to guarantee that at "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"least one domain is consistently allocated to slice zero."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><term>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:249
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#, fuzzy
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#| msgid "ldap_page_size (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid "ldap_idmap_helper_table_size (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr "ldap_page_size (integer)"
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:252
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Maximal number of secondary slices that is tried when performing mapping "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"from UNIX id to SID."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#. type: Content of: <refsect1><refsect2><refsect3><variablelist><varlistentry><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:256
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgid ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"Note: Additional secondary slices might be generated when SID is being "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"mapped to UNIX id and RID part of SID is out of range for secondary slices "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"generated so far. If value of ldap_idmap_helper_table_size is equal to 0 "
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek"then no additional secondary slices are generated."
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozekmsgstr ""
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><title>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:273
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Well-Known SIDs"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:275
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD supports to look up the names of Well-Known SIDs, i.e. SIDs with a "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"special hardcoded meaning. Since the generic users and groups related to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"those Well-Known SIDs have no equivalent in a Linux/UNIX environment no "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"POSIX IDs are available for those objects."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:281
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The SID name space is organized in authorities which can be seen as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"different domains. The authorities for the Well-Known SIDs are"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:284
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Null Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:285
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "World Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:286
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Local Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:287
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Creator Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:288
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "NT Authority"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para><itemizedlist><listitem><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:289
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "Built-in"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:291
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The capitalized version of these names are used as domain names when "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"returning the fully qualified name of a Well-Known SID."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <refsect1><refsect2><para>
f45a20d6ba9e8d695ec3ab707f0cc082999aa4a3Jakub Hrozek#: include/ldap_id_mapping.xml:295
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Since some utilities allow to modify SID based access control information "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"with the help of a name instead of using the SID directly SSSD supports to "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"look up the SID by the name as well. To avoid collisions only the fully "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"qualified names can be used to look up Well-Known SIDs. As a result the "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"domain names <quote>NULL AUTHORITY</quote>, <quote>WORLD AUTHORITY</quote>, "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<quote> LOCAL AUTHORITY</quote>, <quote>CREATOR AUTHORITY</quote>, <quote>NT "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"AUTHORITY</quote> and <quote>BUILTIN</quote> should not be used as domain "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"names in <filename>sssd.conf</filename>."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <varlistentry><term>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#: include/param_help.xml:3
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "<option>-?</option>,<option>--help</option>"
e5c33e0bd03a2deb8e5011deeb3ae93f960910eeJakub Hrozekmsgstr ""
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#. type: Content of: <varlistentry><listitem><para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/param_help.xml:7 include/param_help_py.xml:7
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghermsgid "Display help message and exit."
b355dcb54194f498921743ca33304eac35d89718Stephen Gallaghermsgstr "Exibe a mensagem de ajuda e sai."
056302a92862fda16351d7192600746746f38e5dStephen Gallagher
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <varlistentry><term>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/param_help_py.xml:3
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid "<option>-h</option>,<option>--help</option>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr "<option>-h</option>,<option>--help</option>"
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:3 include/debug_levels_tools.xml:3
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"SSSD supports two representations for specifying the debug level. The "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"simplest is to specify a decimal value from 0-9, which represents enabling "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"that level and all lower-level debug messages. The more comprehensive option "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"is to specify a hexadecimal bitmask to enable or disable specific levels "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"(such as if you wish to suppress a level)."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/debug_levels.xml:10
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"Please note that each SSSD service logs into its own log file. Also please "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"note that enabling <quote>debug_level</quote> in the <quote>[sssd]</quote> "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"section only enables debugging just for the sssd process itself, not for the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"responder or provider processes. The <quote>debug_level</quote> parameter "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"should be added to all sections that you wish to produce debug logs from."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <listitem><para>
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#: include/debug_levels.xml:18
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgid ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"In addition to changing the log level in the config file using the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<quote>debug_level</quote> parameter, which is persistent, but requires SSSD "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"restart, it is also possible to change the debug level on the fly using the "
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"<citerefentry> <refentrytitle>sss_debuglevel</refentrytitle> <manvolnum>8</"
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek"manvolnum> </citerefentry> tool."
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozekmsgstr ""
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek
be5cc3c013ece0c957f2f8c28a217052227dfd07Jakub Hrozek#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:29 include/debug_levels_tools.xml:10
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid "Currently supported debug levels:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:32 include/debug_levels_tools.xml:13
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>0</emphasis>, <emphasis>0x0010</emphasis>: Fatal failures. "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"Anything that would prevent SSSD from starting up or causes it to cease "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"running."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:38 include/debug_levels_tools.xml:19
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>1</emphasis>, <emphasis>0x0020</emphasis>: Critical failures. An "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"error that doesn't kill SSSD, but one that indicates that at least one major "
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek"feature is not going to work properly."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:45 include/debug_levels_tools.xml:26
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>2</emphasis>, <emphasis>0x0040</emphasis>: Serious failures. An "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"error announcing that a particular request or operation has failed."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:50 include/debug_levels_tools.xml:31
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>3</emphasis>, <emphasis>0x0080</emphasis>: Minor failures. These "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"are the errors that would percolate down to cause the operation failure of 2."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:55 include/debug_levels_tools.xml:36
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>4</emphasis>, <emphasis>0x0100</emphasis>: Configuration settings."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:59 include/debug_levels_tools.xml:40
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>5</emphasis>, <emphasis>0x0200</emphasis>: Function data."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:63 include/debug_levels_tools.xml:44
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>6</emphasis>, <emphasis>0x0400</emphasis>: Trace messages for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"operation functions."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:67 include/debug_levels_tools.xml:48
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>7</emphasis>, <emphasis>0x1000</emphasis>: Trace messages for "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"internal control functions."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:72 include/debug_levels_tools.xml:53
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>8</emphasis>, <emphasis>0x2000</emphasis>: Contents of function-"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"internal variables that may be interesting."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:77 include/debug_levels_tools.xml:58
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>9</emphasis>, <emphasis>0x4000</emphasis>: Extremely low-level "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"tracing information."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:81 include/debug_levels_tools.xml:62
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"To log required bitmask debug levels, simply add their numbers together as "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"shown in following examples:"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:85 include/debug_levels_tools.xml:66
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>Example</emphasis>: To log fatal failures, critical failures, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"serious failures and function data use 0x0270."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:89 include/debug_levels_tools.xml:70
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis>Example</emphasis>: To log fatal failures, configuration settings, "
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"function data, trace messages for internal control functions use 0x1310."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:94 include/debug_levels_tools.xml:75
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<emphasis>Note</emphasis>: The bitmask format of debug levels was introduced "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"in 1.7.0."
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#. type: Content of: <listitem><para>
0142e7e2558a887992b1c5d4dc3051178e377687Jakub Hrozek#: include/debug_levels.xml:98 include/debug_levels_tools.xml:79
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozekmsgid "<emphasis>Default</emphasis>: 0"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
292cbb3fbe41bb7ee09b67c3ec59ab7c7ba5220eStephen Gallagher
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#. type: Content of: outside any tag (error?)
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#: include/experimental.xml:1
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgid ""
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"<emphasis> This is an experimental feature, please use http://fedorahosted."
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher"org/sssd to report any issues. </emphasis>"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><title>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:2
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid "THE LOCAL DOMAIN"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:4
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"In order to function correctly, a domain with <quote>id_provider=local</"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"quote> must be created and the SSSD must be running."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#. type: Content of: <refsect1><para>
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher#: include/local.xml:9
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgid ""
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"The administrator might want to use the SSSD local users instead of "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"traditional UNIX users in cases where the group nesting (see <citerefentry> "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<refentrytitle>sss_groupadd</refentrytitle> <manvolnum>8</manvolnum> </"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"citerefentry>) is needed. The local users are also useful for testing and "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"development of the SSSD without having to deploy a full remote server. The "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"<command>sss_user*</command> and <command>sss_group*</command> tools use a "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher"local LDB storage to store users and groups."
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghermsgstr ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#. type: Content of: <refsect1><para>
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek#: include/seealso.xml:4
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgid ""
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<citerefentry> <refentrytitle>sssd</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd.conf</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ldap</refentrytitle><manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd-krb5</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-simple</refentrytitle><manvolnum>5</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sssd-ipa</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>5</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sssd-ad</refentrytitle><manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, <phrase condition=\"with_sudo\"> <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd-sudo</refentrytitle> <manvolnum>5</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, </phrase> <citerefentry> <refentrytitle>sss_cache</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_debuglevel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_groupadd</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_groupdel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_groupshow</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_groupmod</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_useradd</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_userdel</refentrytitle><manvolnum>8</manvolnum> </"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_usermod</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"<refentrytitle>sss_obfuscate</refentrytitle><manvolnum>8</manvolnum> </"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"citerefentry>, <citerefentry> <refentrytitle>sss_seed</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>, <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sssd_krb5_locator_plugin</refentrytitle><manvolnum>8</"
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"manvolnum> </citerefentry>, <phrase condition=\"with_ssh\"> <citerefentry> "
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek"<refentrytitle>sss_ssh_authorizedkeys</refentrytitle> <manvolnum>8</"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozek"manvolnum> </citerefentry>, <citerefentry> "
6463ed1dcdd45416468b3fa178bd856b5a9ed2c3Jakub Hrozek"<refentrytitle>sss_ssh_knownhostsproxy</refentrytitle> <manvolnum>8</"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"manvolnum> </citerefentry>, </phrase> <phrase condition=\"with_ifp\"> "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"<citerefentry> <refentrytitle>sssd-ifp</refentrytitle> <manvolnum>5</"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"manvolnum> </citerefentry>, </phrase> <citerefentry> <refentrytitle>pam_sss</"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"refentrytitle><manvolnum>8</manvolnum> </citerefentry>. <citerefentry> "
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"<refentrytitle>sss_rpcidmapd</refentrytitle> <manvolnum>5</manvolnum> </"
5ee3fba0bd812242a1ffe189f5ddf2689e6e6811Jakub Hrozek"citerefentry>"
64a424ec1b268427822c646f7781e26e56c197f6Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:3
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"An optional base DN, search scope and LDAP filter to restrict LDAP searches "
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"for this attribute type."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
65a9065538fd85e6ead925d344e6b421900eb8c2Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para><programlisting>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:9
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#, no-wrap
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "search_base[?scope?[filter][?search_base?scope?[filter]]*]\n"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:7
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid "syntax: <placeholder type=\"programlisting\" id=\"0\"/>"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#: include/ldap_search_bases.xml:13
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"The scope can be one of \"base\", \"onelevel\" or \"subtree\". The scope "
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"functions as specified in section 4.5.1.2 of http://tools.ietf.org/html/"
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek"rfc4511"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_search_bases.xml:23
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgid ""
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"For examples of this syntax, please refer to the <quote>ldap_search_base</"
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozek"quote> examples section."
7a14e8f66c0e932fe2954d792614a3b61d444bd1Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <listitem><para>
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek#: include/ldap_search_bases.xml:31
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Please note that specifying scope or filter is not supported for searches "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"against an Active Directory Server that might yield a large number of "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"results and trigger the Range Retrieval extension in the response."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#. type: Content of: <para>
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek#: include/autofs_restart.xml:2
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgid ""
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"Please note that the automounter only reads the master map on startup, so if "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"any autofs-related changes are made to the sssd.conf, you typically also "
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozek"need to restart the automounter daemon after restarting the SSSD."
524ceecc11f3d458eb3c1cf1489c3ff6ccb22226Jakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:2
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "override_homedir (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "override_homedir (string)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:16
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "UID number"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "Número UID"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:20
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "domain name"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "nome de domínio"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:23
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%f"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "%f"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:24
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "fully qualified user name (user@domain)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr "nome totalmente qualificado do utilizador (utilizador@domínio)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:28
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgid "UPN - User Principal Name (name@REALM)"
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozekmsgstr ""
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:31
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "%o"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:33
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "The original home directory retrieved from the identity provider."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><term>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:38
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "%H"
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para><variablelist><varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:40
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "The value of configure option <emphasis>homedir_substring</emphasis>."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#: include/override_homedir.xml:5
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"Override the user's home directory. You can either provide an absolute value "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"or a template. In the template, the following sequences are substituted: "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"<placeholder type=\"variablelist\" id=\"0\"/>"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:52
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "This option can also be set per-domain."
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para><programlisting>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:57
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#, no-wrap
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek"override_homedir = /home/%u\n"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek" "
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozek#. type: Content of: <varlistentry><listitem><para>
fbeb1aba9e11e7aab8adac943276ca040f0c5311Jakub Hrozek#: include/override_homedir.xml:61
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgid "Default: Not set (SSSD will use the value retrieved from LDAP)"
2cb6f28b3a12bb714bf14494d31eb6b6fff64b8bJakub Hrozekmsgstr ""
a9228ebcce14888b3123bdf46e610e0900bcd2ccJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><term>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:2
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "homedir_substring (string)"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:5
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid ""
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"The value of this option will be used in the expansion of the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"<emphasis>override_homedir</emphasis> option if the template contains the "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"format string <emphasis>%H</emphasis>. An LDAP directory entry can directly "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"contain this template so that this option can be used to expand the home "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"directory path for each client machine (or operating system). It can be set "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"per-domain or globally in the [nss] section. A value specified in a domain "
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek"section will override one set in the [nss] section."
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgstr ""
a23014d69b56cbdf48ad05229c334648b5309d8fJakub Hrozek
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#. type: Content of: <varlistentry><listitem><para>
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozek#: include/homedir_substring.xml:15
a7797068c4deb6ce2bdbcda27c45ff1bbb4a8e78Jakub Hrozekmsgid "Default: /home"
06c1952db1ab5598e3d68132f9c846bc59c94ef7Jakub Hrozekmsgstr ""