source: vendor/3.5.7/docs/manpages/pam_winbind.8

Last change on this file was 478, checked in by Silvan Scherrer, 15 years ago

Samba 3.5: vendor update to 3.5.4

File size: 10.0 KB
Line 
1.\" Title: pam_winbind
2.\" Author: [see the "AUTHOR" section]
3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
4.\" Date: 06/18/2010
5.\" Manual: 8
6.\" Source: Samba 3.5
7.\" Language: English
8.\"
9.TH "PAM_WINBIND" "8" "06/18/2010" "Samba 3\&.5" "8"
10.\" -----------------------------------------------------------------
11.\" * (re)Define some macros
12.\" -----------------------------------------------------------------
13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
14.\" toupper - uppercase a string (locale-aware)
15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
16.de toupper
17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
18\\$*
19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
20..
21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
22.\" SH-xref - format a cross-reference to an SH section
23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
24.de SH-xref
25.ie n \{\
26.\}
27.toupper \\$*
28.el \{\
29\\$*
30.\}
31..
32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
33.\" SH - level-one heading that works better for non-TTY output
34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
35.de1 SH
36.\" put an extra blank line of space above the head in non-TTY output
37.if t \{\
38.sp 1
39.\}
40.sp \\n[PD]u
41.nr an-level 1
42.set-an-margin
43.nr an-prevailing-indent \\n[IN]
44.fi
45.in \\n[an-margin]u
46.ti 0
47.HTML-TAG ".NH \\n[an-level]"
48.it 1 an-trap
49.nr an-no-space-flag 1
50.nr an-break-flag 1
51\." make the size of the head bigger
52.ps +3
53.ft B
54.ne (2v + 1u)
55.ie n \{\
56.\" if n (TTY output), use uppercase
57.toupper \\$*
58.\}
59.el \{\
60.nr an-break-flag 0
61.\" if not n (not TTY), use normal case (not uppercase)
62\\$1
63.in \\n[an-margin]u
64.ti 0
65.\" if not n (not TTY), put a border/line under subheading
66.sp -.6
67\l'\n(.lu'
68.\}
69..
70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
71.\" SS - level-two heading that works better for non-TTY output
72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
73.de1 SS
74.sp \\n[PD]u
75.nr an-level 1
76.set-an-margin
77.nr an-prevailing-indent \\n[IN]
78.fi
79.in \\n[IN]u
80.ti \\n[SN]u
81.it 1 an-trap
82.nr an-no-space-flag 1
83.nr an-break-flag 1
84.ps \\n[PS-SS]u
85\." make the size of the head bigger
86.ps +2
87.ft B
88.ne (2v + 1u)
89.if \\n[.$] \&\\$*
90..
91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
92.\" BB/BE - put background/screen (filled box) around block of text
93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
94.de BB
95.if t \{\
96.sp -.5
97.br
98.in +2n
99.ll -2n
100.gcolor red
101.di BX
102.\}
103..
104.de EB
105.if t \{\
106.if "\\$2"adjust-for-leading-newline" \{\
107.sp -1
108.\}
109.br
110.di
111.in
112.ll
113.gcolor
114.nr BW \\n(.lu-\\n(.i
115.nr BH \\n(dn+.5v
116.ne \\n(BHu+.5v
117.ie "\\$2"adjust-for-leading-newline" \{\
118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
119.\}
120.el \{\
121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
122.\}
123.in 0
124.sp -.5v
125.nf
126.BX
127.in
128.sp .5v
129.fi
130.\}
131..
132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
133.\" BM/EM - put colored marker in margin next to block of text
134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
135.de BM
136.if t \{\
137.br
138.ll -2n
139.gcolor red
140.di BX
141.\}
142..
143.de EM
144.if t \{\
145.br
146.di
147.ll
148.gcolor
149.nr BH \\n(dn
150.ne \\n(BHu
151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
152.in 0
153.nf
154.BX
155.in
156.fi
157.\}
158..
159.\" -----------------------------------------------------------------
160.\" * set default formatting
161.\" -----------------------------------------------------------------
162.\" disable hyphenation
163.nh
164.\" disable justification (adjust text to left margin only)
165.ad l
166.\" -----------------------------------------------------------------
167.\" * MAIN CONTENT STARTS HERE *
168.\" -----------------------------------------------------------------
169.SH "Name"
170pam_winbind \- PAM module for Winbind
171.SH "DESCRIPTION"
172.PP
173This tool is part of the
174\fBsamba\fR(7)
175suite\&.
176.PP
177pam_winbind is a PAM module that can authenticate users against the local domain by talking to the Winbind daemon\&.
178.SH "SYNOPSIS"
179.PP
180Edit the PAM system config /etc/pam\&.d/service and modify it as the following example shows:
181.sp
182.if n \{\
183.RS 4
184.\}
185.fam C
186.ps -1
187.nf
188.if t \{\
189.sp -1
190.\}
191.BB lightgray adjust-for-leading-newline
192.sp -1
193
194 \&.\&.\&.
195 auth required pam_env\&.so
196 auth sufficient pam_unix2\&.so
197 +++ auth required pam_winbind\&.so use_first_pass
198 account requisite pam_unix2\&.so
199 +++ account required pam_winbind\&.so use_first_pass
200 +++ password sufficient pam_winbind\&.so
201 password requisite pam_pwcheck\&.so cracklib
202 password required pam_unix2\&.so use_authtok
203 session required pam_unix2\&.so
204 +++ session required pam_winbind\&.so
205 \&.\&.\&.
206
207.EB lightgray adjust-for-leading-newline
208.if t \{\
209.sp 1
210.\}
211.fi
212.fam
213.ps +1
214.if n \{\
215.RE
216.\}
217.sp
218Make sure that pam_winbind is one of the first modules in the session part\&. It may retrieve kerberos tickets which are needed by other modules\&.
219.SH "OPTIONS"
220.PP
221pam_winbind supports several options which can either be set in the PAM configuration files or in the pam_winbind configuration file situated at
222\FC/etc/security/pam_winbind\&.conf\F[]\&. Options from the PAM configuration file take precedence to those from the configuration file\&. See
223\fBpam_winbind.conf\fR(5)
224for further details\&.
225.PP
226debug
227.RS 4
228Gives debugging output to syslog\&.
229.RE
230.PP
231debug_state
232.RS 4
233Gives detailed PAM state debugging output to syslog\&.
234.RE
235.PP
236require_membership_of=[SID or NAME]
237.RS 4
238If this option is set, pam_winbind will only succeed if the user is a member of the given SID or NAME\&. A SID can be either a group\-SID, an alias\-SID or even an user\-SID\&. It is also possible to give a NAME instead of the SID\&. That name must have the form:
239\fIMYDOMAIN\e\emygroup\fR
240or
241\fIMYDOMAIN\e\emyuser\fR\&. pam_winbind will, in that case, lookup the SID internally\&. Note that NAME may not contain any spaces\&. It is thus recommended to only use SIDs\&. You can verify the list of SIDs a user is a member of with
242\FCwbinfo \-\-user\-sids=SID\F[]\&.
243.RE
244.PP
245use_first_pass
246.RS 4
247By default, pam_winbind tries to get the authentication token from a previous module\&. If no token is available it asks the user for the old password\&. With this option, pam_winbind aborts with an error if no authentication token from a previous module is available\&.
248.RE
249.PP
250try_first_pass
251.RS 4
252Same as the use_first_pass option (previous item), except that if the primary password is not valid, PAM will prompt for a password\&.
253.RE
254.PP
255use_authtok
256.RS 4
257Set the new password to the one provided by the previously stacked password module\&. If this option is not set pam_winbind will ask the user for the new password\&.
258.RE
259.PP
260krb5_auth
261.RS 4
262pam_winbind can authenticate using Kerberos when winbindd is talking to an Active Directory domain controller\&. Kerberos authentication must be enabled with this parameter\&. When Kerberos authentication can not succeed (e\&.g\&. due to clock skew), winbindd will fallback to samlogon authentication over MSRPC\&. When this parameter is used in conjunction with
263\fIwinbind refresh tickets\fR, winbind will keep your Ticket Granting Ticket (TGT) uptodate by refreshing it whenever necessary\&.
264.RE
265.PP
266krb5_ccache_type=[type]
267.RS 4
268When pam_winbind is configured to try kerberos authentication by enabling the
269\fIkrb5_auth\fR
270option, it can store the retrieved Ticket Granting Ticket (TGT) in a credential cache\&. The type of credential cache can be set with this option\&. Currently the only supported value is:
271\fIFILE\fR\&. In that case a credential cache in the form of /tmp/krb5cc_UID will be created, where UID is replaced with the numeric user id\&. Leave empty to just do kerberos authentication without having a ticket cache after the logon has succeeded\&.
272.RE
273.PP
274cached_login
275.RS 4
276Winbind allows to logon using cached credentials when
277\fIwinbind offline logon\fR
278is enabled\&. To use this feature from the PAM module this option must be set\&.
279.RE
280.PP
281silent
282.RS 4
283Do not emit any messages\&.
284.RE
285.PP
286mkhomedir
287.RS 4
288Create homedirectory for a user on\-the\-fly, option is valid in PAM session block\&.
289.RE
290.PP
291warn_pwd_expire
292.RS 4
293Defines number of days before pam_winbind starts to warn about passwords that are going to expire\&. Defaults to 14 days\&.
294.RE
295.SH "PAM DATA EXPORTS"
296.PP
297This section describes the data exported in the PAM stack which could be used in other PAM modules\&.
298.PP
299PAM_WINBIND_HOMEDIR
300.RS 4
301This is the Windows Home Directory set in the profile tab in the user settings on the Active Directory Server\&. This could be a local path or a directory on a share mapped to a drive\&.
302.RE
303.PP
304PAM_WINBIND_LOGONSCRIPT
305.RS 4
306The path to the logon script which should be executed if a user logs in\&. This is normally a relative path to the script stored on the server\&.
307.RE
308.PP
309PAM_WINBIND_LOGONSERVER
310.RS 4
311This exports the Active Directory server we are authenticating against\&. This can be used as a variable later\&.
312.RE
313.PP
314PAM_WINBIND_PROFILEPATH
315.RS 4
316This is the profile path set in the profile tab in the user settings\&. Normally the home directory is synced with this directory on a share\&.
317.RE
318.SH "SEE ALSO"
319.PP
320\fBpam_winbind.conf\fR(5),
321\fBwbinfo\fR(1),
322\fBwinbindd\fR(8),
323\fBsmb.conf\fR(5)
324.SH "VERSION"
325.PP
326This man page is correct for version 3 of Samba\&.
327.SH "AUTHOR"
328.PP
329The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&.
330.PP
331This manpage was written by Jelmer Vernooij and Guenther Deschner\&.
Note: See TracBrowser for help on using the repository browser.