source: vendor/current/docs/manpages/wbinfo.1

Last change on this file was 989, checked in by Silvan Scherrer, 9 years ago

Samba Server: update vendor to version 4.4.7

File size: 12.3 KB
Line 
1'\" t
2.\" Title: wbinfo
3.\" Author: [see the "AUTHOR" section]
4.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
5.\" Date: 10/25/2016
6.\" Manual: User Commands
7.\" Source: Samba 4.4
8.\" Language: English
9.\"
10.TH "WBINFO" "1" "10/25/2016" "Samba 4\&.4" "User Commands"
11.\" -----------------------------------------------------------------
12.\" * Define some portability stuff
13.\" -----------------------------------------------------------------
14.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
15.\" http://bugs.debian.org/507673
16.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
17.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
18.ie \n(.g .ds Aq \(aq
19.el .ds Aq '
20.\" -----------------------------------------------------------------
21.\" * set default formatting
22.\" -----------------------------------------------------------------
23.\" disable hyphenation
24.nh
25.\" disable justification (adjust text to left margin only)
26.ad l
27.\" -----------------------------------------------------------------
28.\" * MAIN CONTENT STARTS HERE *
29.\" -----------------------------------------------------------------
30.SH "NAME"
31wbinfo \- Query information from winbind daemon
32.SH "SYNOPSIS"
33.HP \w'\ 'u
34wbinfo [\-a\ user%password] [\-\-all\-domains] [\-\-allocate\-gid] [\-\-allocate\-uid] [\-c] [\-\-ccache\-save] [\-\-change\-user\-password] [\-D\ domain] [\-\-dc\-info\ domain] [\-\-domain\ domain] [\-\-dsgetdcname\ domain] [\-g] [\-\-getdcname\ domain] [\-\-get\-auth\-user] [\-G\ gid] [\-\-gid\-info\ gid] [\-\-group\-info\ group] [\-\-help|\-?] [\-i\ user] [\-I\ ip] [\-K\ user%password] [\-\-krb5ccname\ cctype] [\-\-lanman] [\-\-logoff] [\-\-logoff\-uid\ uid] [\-\-logoff\-user\ username] [\-\-lookup\-sids] [\-m] [\-n\ name] [\-N\ netbios\-name] [\-\-ntlmv2] [\-\-online\-status] [\-\-own\-domain] [\-p] [\-P|\-\-ping\-dc] [\-\-pam\-logon\ user%password] [\-r\ user] [\-R|\-\-lookup\-rids] [\-\-remove\-gid\-mapping\ gid,sid] [\-\-remove\-uid\-mapping\ uid,sid] [\-s\ sid] [\-\-separator] [\-\-sequence] [\-\-set\-auth\-user\ user%password] [\-\-set\-gid\-mapping\ gid,sid] [\-\-set\-uid\-mapping\ uid,sid] [\-S\ sid] [\-\-sid\-aliases\ sid] [\-\-sid\-to\-fullname\ sid] [\-\-sids\-to\-unix\-ids\ sidlist] [\-t] [\-u] [\-\-uid\-info\ uid] [\-\-usage] [\-\-user\-domgroups\ sid] [\-\-user\-sidinfo\ sid] [\-\-user\-sids\ sid] [\-U\ uid] [\-V] [\-\-verbose] [\-Y\ sid]
35.SH "DESCRIPTION"
36.PP
37This tool is part of the
38\fBsamba\fR(7)
39suite\&.
40.PP
41The
42wbinfo
43program queries and returns information created and used by the
44\fBwinbindd\fR(8)
45daemon\&.
46.PP
47The
48\fBwinbindd\fR(8)
49daemon must be configured and running for the
50wbinfo
51program to be able to return information\&.
52.SH "OPTIONS"
53.PP
54\-a|\-\-authenticate \fIusername%password\fR
55.RS 4
56Attempt to authenticate a user via
57\fBwinbindd\fR(8)\&. This checks both authentication methods and reports its results\&.
58.if n \{\
59.sp
60.\}
61.RS 4
62.it 1 an-trap
63.nr an-no-space-flag 1
64.nr an-break-flag 1
65.br
66.ps +1
67\fBNote\fR
68.ps -1
69.br
70Do not be tempted to use this functionality for authentication in third\-party applications\&. Instead use
71\fBntlm_auth\fR(1)\&.
72.sp .5v
73.RE
74.RE
75.PP
76\-\-allocate\-gid
77.RS 4
78Get a new GID out of idmap
79.RE
80.PP
81\-\-allocate\-uid
82.RS 4
83Get a new UID out of idmap
84.RE
85.PP
86\-\-all\-domains
87.RS 4
88List all domains (trusted and own domain)\&.
89.RE
90.PP
91\-c|\-\-change\-secret
92.RS 4
93Change the trust account password\&. May be used in conjunction with
94\fBdomain\fR
95in order to change interdomain trust account passwords\&.
96.RE
97.PP
98\-\-ccache\-save \fIusername%password\fR
99.RS 4
100Store user and password for ccache\&.
101.RE
102.PP
103\-\-change\-user\-password \fIusername\fR
104.RS 4
105Change the password of a user\&. The old and new password will be prompted\&.
106.RE
107.PP
108\-\-dc\-info \fIdomain\fR
109.RS 4
110Displays information about the current domain controller for a domain\&.
111.RE
112.PP
113\-\-domain \fIname\fR
114.RS 4
115This parameter sets the domain on which any specified operations will performed\&. If special domain name \*(Aq\&.\*(Aq is used to represent the current domain to which
116\fBwinbindd\fR(8)
117belongs\&. A \*(Aq*\*(Aq as the domain name means to enumerate over all domains (NOTE: This can take a long time and use a lot of memory)\&.
118.RE
119.PP
120\-D|\-\-domain\-info \fIdomain\fR
121.RS 4
122Show most of the info we have about the specified domain\&.
123.RE
124.PP
125\-\-dsgetdcname \fIdomain\fR
126.RS 4
127Find a DC for a domain\&.
128.RE
129.PP
130\-\-gid\-info \fIgid\fR
131.RS 4
132Get group info from gid\&.
133.RE
134.PP
135\-\-group\-info \fIgroup\fR
136.RS 4
137Get group info from group name\&.
138.RE
139.PP
140\-g|\-\-domain\-groups
141.RS 4
142This option will list all groups available in the Windows NT domain for which the
143\fBsamba\fR(7)
144daemon is operating in\&. Groups in all trusted domains can be listed with the \-\-domain=\*(Aq*\*(Aq option\&. Note that this operation does not assign group ids to any groups that have not already been seen by
145\fBwinbindd\fR(8)\&.
146.RE
147.PP
148\-\-get\-auth\-user
149.RS 4
150Print username and password used by
151\fBwinbindd\fR(8)
152during session setup to a domain controller\&. Username and password can be set using
153\fB\-\-set\-auth\-user\fR\&. Only available for root\&.
154.RE
155.PP
156\-\-getdcname \fIdomain\fR
157.RS 4
158Get the DC name for the specified domain\&.
159.RE
160.PP
161\-G|\-\-gid\-to\-sid \fIgid\fR
162.RS 4
163Try to convert a UNIX group id to a Windows NT SID\&. If the gid specified does not refer to one within the idmap gid range then the operation will fail\&.
164.RE
165.PP
166\-?
167.RS 4
168Print brief help overview\&.
169.RE
170.PP
171\-i|\-\-user\-info \fIuser\fR
172.RS 4
173Get user info\&.
174.RE
175.PP
176\-I|\-\-WINS\-by\-ip \fIip\fR
177.RS 4
178The
179\fI\-I\fR
180option queries
181\fBwinbindd\fR(8)
182to send a node status request to get the NetBIOS name associated with the IP address specified by the
183\fIip\fR
184parameter\&.
185.RE
186.PP
187\-K|\-\-krb5auth \fIusername%password\fR
188.RS 4
189Attempt to authenticate a user via Kerberos\&.
190.RE
191.PP
192\-\-krb5ccname \fIKRB5CCNAME\fR
193.RS 4
194Allows one to request a sepcific kerberos credential cache type used for authentication\&.
195.RE
196.PP
197\-\-lanman
198.RS 4
199Use lanman cryptography for user authentication\&.
200.RE
201.PP
202\-\-logoff
203.RS 4
204Logoff a user\&.
205.RE
206.PP
207\-\-logoff\-uid \fIUID\fR
208.RS 4
209Define user uid used during logoff request\&.
210.RE
211.PP
212\-\-logoff\-user \fIUSERNAME\fR
213.RS 4
214Define username used during logoff request\&.
215.RE
216.PP
217\-\-lookup\-sids \fISID1,SID2\&.\&.\&.\fR
218.RS 4
219Looks up SIDs\&. SIDs must be specified as ASCII strings in the traditional Microsoft format\&. For example, S\-1\-5\-21\-1455342024\-3071081365\-2475485837\-500\&.
220.RE
221.PP
222\-m|\-\-trusted\-domains
223.RS 4
224Produce a list of domains trusted by the Windows NT server
225\fBwinbindd\fR(8)
226contacts when resolving names\&. This list does not include the Windows NT domain the server is a Primary Domain Controller for\&.
227.RE
228.PP
229\-n|\-\-name\-to\-sid \fIname\fR
230.RS 4
231The
232\fI\-n\fR
233option queries
234\fBwinbindd\fR(8)
235for the SID associated with the name specified\&. Domain names can be specified before the user name by using the winbind separator character\&. For example CWDOM1/Administrator refers to the Administrator user in the domain CWDOM1\&. If no domain is specified then the domain used is the one specified in the
236\fBsmb.conf\fR(5)\fIworkgroup \fR
237parameter\&.
238.RE
239.PP
240\-N|\-\-WINS\-by\-name \fIname\fR
241.RS 4
242The
243\fI\-N\fR
244option queries
245\fBwinbindd\fR(8)
246to query the WINS server for the IP address associated with the NetBIOS name specified by the
247\fIname\fR
248parameter\&.
249.RE
250.PP
251\-\-ntlmv2
252.RS 4
253Use NTLMv2 cryptography for user authentication\&.
254.RE
255.PP
256\-\-online\-status \fIdomain\fR
257.RS 4
258Show whether domains are marked as online or offline\&. An optional domain argument limits the output to the online status of a given domain\&.
259.RE
260.PP
261\-\-own\-domain
262.RS 4
263List own domain\&.
264.RE
265.PP
266\-\-pam\-logon \fIusername%password\fR
267.RS 4
268Attempt to authenticate a user in the same way pam_winbind would do\&.
269.RE
270.PP
271\-p|\-\-ping
272.RS 4
273Check whether
274\fBwinbindd\fR(8)
275is still alive\&. Prints out either \*(Aqsucceeded\*(Aq or \*(Aqfailed\*(Aq\&.
276.RE
277.PP
278\-P|\-\-ping\-dc
279.RS 4
280Issue a no\-effect command to our DC\&. This checks if our secure channel connection to our domain controller is still alive\&. It has much less impact than wbinfo \-t\&.
281.RE
282.PP
283\-r|\-\-user\-groups \fIusername\fR
284.RS 4
285Try to obtain the list of UNIX group ids to which the user belongs\&. This only works for users defined on a Domain Controller\&.
286.RE
287.PP
288\-R|\-\-lookup\-rids \fIrid1, rid2, rid3\&.\&.\&.\fR
289.RS 4
290Converts RIDs to names\&. Uses a comma separated list of rids\&.
291.RE
292.PP
293\-\-remove\-gid\-mapping \fIGID,SID\fR
294.RS 4
295Removes an existing GID to SID mapping from the database\&.
296.RE
297.PP
298\-\-remove\-uid\-mapping \fIUID,SID\fR
299.RS 4
300Removes an existing UID to SID mapping from the database\&.
301.RE
302.PP
303\-s|\-\-sid\-to\-name \fIsid\fR
304.RS 4
305Use
306\fI\-s\fR
307to resolve a SID to a name\&. This is the inverse of the
308\fI\-n \fR
309option above\&. SIDs must be specified as ASCII strings in the traditional Microsoft format\&. For example, S\-1\-5\-21\-1455342024\-3071081365\-2475485837\-500\&.
310.RE
311.PP
312\-\-separator
313.RS 4
314Get the active winbind separator\&.
315.RE
316.PP
317\-\-sequence
318.RS 4
319This command has been deprecated\&. Please use the \-\-online\-status option instead\&.
320.RE
321.PP
322\-\-set\-auth\-user \fIusername%password\fR
323.RS 4
324Store username and password used by
325\fBwinbindd\fR(8)
326during session setup to a domain controller\&. This enables winbindd to operate in a Windows 2000 domain with Restrict Anonymous turned on (a\&.k\&.a\&. Permissions compatible with Windows 2000 servers only)\&.
327.RE
328.PP
329\-\-set\-gid\-mapping \fIGID,SID\fR
330.RS 4
331Create a GID to SID mapping in the database\&.
332.RE
333.PP
334\-\-set\-uid\-mapping \fIUID,SID\fR
335.RS 4
336Create a UID to SID mapping in the database\&.
337.RE
338.PP
339\-S|\-\-sid\-to\-uid \fIsid\fR
340.RS 4
341Convert a SID to a UNIX user id\&. If the SID does not correspond to a UNIX user mapped by
342\fBwinbindd\fR(8)
343then the operation will fail\&.
344.RE
345.PP
346\-\-sid\-aliases \fIsid\fR
347.RS 4
348Get SID aliases for a given SID\&.
349.RE
350.PP
351\-\-sid\-to\-fullname \fIsid\fR
352.RS 4
353Converts a SID to a full username (DOMAIN\eusername)\&.
354.RE
355.PP
356\-\-sids\-to\-unix\-ids \fIsid1,sid2,sid3\&.\&.\&.\fR
357.RS 4
358Resolve SIDs to Unix IDs\&. SIDs must be specified as ASCII strings in the traditional Microsoft format\&. For example, S\-1\-5\-21\-1455342024\-3071081365\-2475485837\-500\&.
359.RE
360.PP
361\-t|\-\-check\-secret
362.RS 4
363Verify that the workstation trust account created when the Samba server is added to the Windows NT domain is working\&. May be used in conjunction with
364\fBdomain\fR
365in order to verify interdomain trust accounts\&.
366.RE
367.PP
368\-u|\-\-domain\-users
369.RS 4
370This option will list all users available in the Windows NT domain for which the
371\fBwinbindd\fR(8)
372daemon is operating in\&. Users in all trusted domains can be listed with the \-\-domain=\*(Aq*\*(Aq option\&. Note that this operation does not assign user ids to any users that have not already been seen by
373\fBwinbindd\fR(8)
374\&.
375.RE
376.PP
377\-\-uid\-info \fIuid\fR
378.RS 4
379Get user info for the user connected to user id UID\&.
380.RE
381.PP
382\-\-usage
383.RS 4
384Print brief help overview\&.
385.RE
386.PP
387\-\-user\-domgroups \fIsid\fR
388.RS 4
389Get user domain groups\&.
390.RE
391.PP
392\-\-user\-sidinfo \fIsid\fR
393.RS 4
394Get user info by sid\&.
395.RE
396.PP
397\-\-user\-sids \fIsid\fR
398.RS 4
399Get user group SIDs for user\&.
400.RE
401.PP
402\-U|\-\-uid\-to\-sid \fIuid\fR
403.RS 4
404Try to convert a UNIX user id to a Windows NT SID\&. If the uid specified does not refer to one within the idmap range then the operation will fail\&.
405.RE
406.PP
407\-\-verbose
408.RS 4
409Print additional information about the query results\&.
410.RE
411.PP
412\-Y|\-\-sid\-to\-gid \fIsid\fR
413.RS 4
414Convert a SID to a UNIX group id\&. If the SID does not correspond to a UNIX group mapped by
415\fBwinbindd\fR(8)
416then the operation will fail\&.
417.RE
418.SH "EXIT STATUS"
419.PP
420The wbinfo program returns 0 if the operation succeeded, or 1 if the operation failed\&. If the
421\fBwinbindd\fR(8)
422daemon is not working
423wbinfo
424will always return failure\&.
425.SH "VERSION"
426.PP
427This man page is correct for version 3 of the Samba suite\&.
428.SH "SEE ALSO"
429.PP
430\fBwinbindd\fR(8)
431and
432\fBntlm_auth\fR(1)
433.SH "AUTHOR"
434.PP
435The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&.
436.PP
437wbinfo
438and
439winbindd
440were written by Tim Potter\&.
441.PP
442The conversion to DocBook for Samba 2\&.2 was done by Gerald Carter\&. The conversion to DocBook XML 4\&.2 for Samba 3\&.0 was done by Alexander Bokovoy\&.
Note: See TracBrowser for help on using the repository browser.