- Timestamp:
- May 27, 2009, 9:08:03 AM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.2.x/docs/htmldocs/manpages/winbindd.8.html
r226 r231 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>winbindd</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.7 3.1"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en"><a name="winbindd.8"></a><div class="titlepage"></div><div class="refnamediv"><h2>Name</h2><p>winbindd — Name Service Switch daemon for resolving names2 from NT servers</p></div><div class="refsynopsisdiv"><h2>Synopsis</h2><div class="cmdsynopsis"><p><code class="literal">winbindd</code> [-D] [-F] [-S] [-i] [-Y] [-d <debug level>] [-s <smb config file>] [-n]</p></div></div><div class="refsect1" lang="en"><a name="id24 79186"></a><h2>DESCRIPTION</h2><p>This program is part of the <a class="citerefentry" href="samba.7.html"><span class="citerefentry"><span class="refentrytitle">samba</span>(7)</span></a> suite.</p><p><code class="literal">winbindd</code> is a daemon that provides1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>winbindd</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en"><a name="winbindd.8"></a><div class="titlepage"></div><div class="refnamediv"><h2>Name</h2><p>winbindd — Name Service Switch daemon for resolving names 2 from NT servers</p></div><div class="refsynopsisdiv"><h2>Synopsis</h2><div class="cmdsynopsis"><p><code class="literal">winbindd</code> [-D] [-F] [-S] [-i] [-Y] [-d <debug level>] [-s <smb config file>] [-n]</p></div></div><div class="refsect1" lang="en"><a name="id2483363"></a><h2>DESCRIPTION</h2><p>This program is part of the <a class="citerefentry" href="samba.7.html"><span class="citerefentry"><span class="refentrytitle">samba</span>(7)</span></a> suite.</p><p><code class="literal">winbindd</code> is a daemon that provides 3 3 a number of services to the Name Service Switch capability found 4 4 in most modern C libraries, to arbitrary applications via PAM … … 7 7 and the <code class="literal">pam_winbind.so</code> PAM module, by managing connections to 8 8 domain controllers. In this configuraiton the 9 <a class="link" href="smb.conf.5.html#IDMAPUID" >idmap uid</a> and10 <a class="link" href="smb.conf.5.html#IDMAPGID" >idmap gid</a>9 <a class="link" href="smb.conf.5.html#IDMAPUID" target="_top">idmap uid</a> and 10 <a class="link" href="smb.conf.5.html#IDMAPGID" target="_top">idmap gid</a> 11 11 parameters are not required. (This is known as `netlogon proxy only mode'.)</p><p> The Name Service Switch allows user 12 12 and system information to be obtained from different databases … … 61 61 WINS server.</p><pre class="programlisting"> 62 62 hosts: files wins 63 </pre></div><div class="refsect1" lang="en"><a name="id24 78342"></a><h2>OPTIONS</h2><div class="variablelist"><dl><dt><span class="term">-F</span></dt><dd><p>If specified, this parameter causes63 </pre></div><div class="refsect1" lang="en"><a name="id2481563"></a><h2>OPTIONS</h2><div class="variablelist"><dl><dt><span class="term">-F</span></dt><dd><p>If specified, this parameter causes 64 64 the main <code class="literal">winbindd</code> process to not daemonize, 65 65 i.e. double-fork and disassociate with the terminal. … … 85 85 use only by developers and generate HUGE amounts of log 86 86 data, most of which is extremely cryptic.</p><p>Note that specifying this parameter here will 87 override the <a class="link" href="smb.conf.5.html#LOGLEVEL" >log level</a> parameter87 override the <a class="link" href="smb.conf.5.html#LOGLEVEL" target="_top">log level</a> parameter 88 88 in the <code class="filename">smb.conf</code> file.</p></dd><dt><span class="term">-V</span></dt><dd><p>Prints the program version number. 89 89 </p></dd><dt><span class="term">-s <configuration file></span></dt><dd><p>The file specified contains the … … 114 114 default behavior is to launch a child process that is responsible for 115 115 updating expired cache entries. 116 </p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id24 78606"></a><h2>NAME AND ID RESOLUTION</h2><p>Users and groups on a Windows NT server are assigned116 </p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id2481823"></a><h2>NAME AND ID RESOLUTION</h2><p>Users and groups on a Windows NT server are assigned 117 117 a security id (SID) which is globally unique when the 118 118 user or group is created. To convert the Windows NT user or group … … 128 128 store is deleted or corrupted, there is no way for winbindd to 129 129 determine which user and group ids correspond to Windows NT user 130 and group rids. </p><p>See the <a class="link" href="smb.conf.5.html#IDMAPDOMAINS" >idmap domains</a> or the old <a class="link" href="smb.conf.5.html#IDMAPBACKEND">idmap backend</a> parameters in130 and group rids. </p><p>See the <a class="link" href="smb.conf.5.html#IDMAPDOMAINS" target="_top">idmap domains</a> or the old <a class="link" href="smb.conf.5.html#IDMAPBACKEND" target="_top">idmap backend</a> parameters in 131 131 <code class="filename">smb.conf</code> for options for sharing this 132 database, such as via LDAP.</p></div><div class="refsect1" lang="en"><a name="id24 78680"></a><h2>CONFIGURATION</h2><p>Configuration of the <code class="literal">winbindd</code> daemon132 database, such as via LDAP.</p></div><div class="refsect1" lang="en"><a name="id2481893"></a><h2>CONFIGURATION</h2><p>Configuration of the <code class="literal">winbindd</code> daemon 133 133 is done through configuration parameters in the <a class="citerefentry" href="smb.conf.5.html"><span class="citerefentry"><span class="refentrytitle">smb.conf</span>(5)</span></a> file. All parameters should be specified in the 134 134 [global] section of smb.conf. </p><div class="itemizedlist"><ul type="disc"><li><p> 135 <a class="link" href="smb.conf.5.html#WINBINDSEPARATOR" >winbind separator</a></p></li><li><p>136 <a class="link" href="smb.conf.5.html#IDMAPUID" >idmap uid</a></p></li><li><p>137 <a class="link" href="smb.conf.5.html#IDMAPGID" >idmap gid</a></p></li><li><p>138 <a class="link" href="smb.conf.5.html#IDMAPBACKEND" >idmap backend</a></p></li><li><p>139 <a class="link" href="smb.conf.5.html#WINBINDCACHETIME" >winbind cache time</a></p></li><li><p>140 <a class="link" href="smb.conf.5.html#WINBINDENUMUSERS" >winbind enum users</a></p></li><li><p>141 <a class="link" href="smb.conf.5.html#WINBINDENUMGROUPS" >winbind enum groups</a></p></li><li><p>142 <a class="link" href="smb.conf.5.html#TEMPLATEHOMEDIR" >template homedir</a></p></li><li><p>143 <a class="link" href="smb.conf.5.html#TEMPLATESHELL" >template shell</a></p></li><li><p>144 <a class="link" href="smb.conf.5.html#WINBINDUSEDEFAULTDOMAIN" >winbind use default domain</a></p></li><li><p>145 <a class="link" href="smb.conf.5.html#WINBIND:RPCONLY" >winbind: rpc only</a>135 <a class="link" href="smb.conf.5.html#WINBINDSEPARATOR" target="_top">winbind separator</a></p></li><li><p> 136 <a class="link" href="smb.conf.5.html#IDMAPUID" target="_top">idmap uid</a></p></li><li><p> 137 <a class="link" href="smb.conf.5.html#IDMAPGID" target="_top">idmap gid</a></p></li><li><p> 138 <a class="link" href="smb.conf.5.html#IDMAPBACKEND" target="_top">idmap backend</a></p></li><li><p> 139 <a class="link" href="smb.conf.5.html#WINBINDCACHETIME" target="_top">winbind cache time</a></p></li><li><p> 140 <a class="link" href="smb.conf.5.html#WINBINDENUMUSERS" target="_top">winbind enum users</a></p></li><li><p> 141 <a class="link" href="smb.conf.5.html#WINBINDENUMGROUPS" target="_top">winbind enum groups</a></p></li><li><p> 142 <a class="link" href="smb.conf.5.html#TEMPLATEHOMEDIR" target="_top">template homedir</a></p></li><li><p> 143 <a class="link" href="smb.conf.5.html#TEMPLATESHELL" target="_top">template shell</a></p></li><li><p> 144 <a class="link" href="smb.conf.5.html#WINBINDUSEDEFAULTDOMAIN" target="_top">winbind use default domain</a></p></li><li><p> 145 <a class="link" href="smb.conf.5.html#WINBIND:RPCONLY" target="_top">winbind: rpc only</a> 146 146 Setting this parameter forces winbindd to use RPC 147 147 instead of LDAP to retrieve information from Domain 148 148 Controllers. 149 </p></li></ul></div></div><div class="refsect1" lang="en"><a name="id25 25540"></a><h2>EXAMPLE SETUP</h2><p>149 </p></li></ul></div></div><div class="refsect1" lang="en"><a name="id2532543"></a><h2>EXAMPLE SETUP</h2><p> 150 150 To setup winbindd for user and group lookups plus 151 151 authentication from a domain controller use something like the … … 198 198 the DOMAIN+user syntax for the username. You may wish to use the 199 199 commands <code class="literal">getent passwd</code> and <code class="literal">getent group 200 </code> to confirm the correct operation of winbindd.</p></div><div class="refsect1" lang="en"><a name="id25 25748"></a><h2>NOTES</h2><p>The following notes are useful when configuring and200 </code> to confirm the correct operation of winbindd.</p></div><div class="refsect1" lang="en"><a name="id2532734"></a><h2>NOTES</h2><p>The following notes are useful when configuring and 201 201 running <code class="literal">winbindd</code>: </p><p><a class="citerefentry" href="nmbd.8.html"><span class="citerefentry"><span class="refentrytitle">nmbd</span>(8)</span></a> must be running on the local machine 202 202 for <code class="literal">winbindd</code> to work. </p><p>PAM is really easy to misconfigure. Make sure you know what … … 205 205 then in general the user and groups ids allocated by winbindd will not 206 206 be the same. The user and group ids will only be valid for the local 207 machine, unless a shared <a class="link" href="smb.conf.5.html#IDMAPBACKEND" >idmap backend</a> is configured.</p><p>If the the Windows NT SID to UNIX user and group id mapping208 file is damaged or destroyed then the mappings will be lost. </p></div><div class="refsect1" lang="en"><a name="id25 25820"></a><h2>SIGNALS</h2><p>The following signals can be used to manipulate the207 machine, unless a shared <a class="link" href="smb.conf.5.html#IDMAPBACKEND" target="_top">idmap backend</a> is configured.</p><p>If the the Windows NT SID to UNIX user and group id mapping 208 file is damaged or destroyed then the mappings will be lost. </p></div><div class="refsect1" lang="en"><a name="id2532799"></a><h2>SIGNALS</h2><p>The following signals can be used to manipulate the 209 209 <code class="literal">winbindd</code> daemon. </p><div class="variablelist"><dl><dt><span class="term">SIGHUP</span></dt><dd><p>Reload the <a class="citerefentry" href="smb.conf.5.html"><span class="citerefentry"><span class="refentrytitle">smb.conf</span>(5)</span></a> file and 210 210 apply any parameter changes to the running … … 214 214 winbindd</code> to write status information to the winbind 215 215 log file.</p><p>Log files are stored in the filename specified by the 216 log file parameter.</p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id25 25885"></a><h2>FILES</h2><div class="variablelist"><dl><dt><span class="term"><code class="filename">/etc/nsswitch.conf(5)</code></span></dt><dd><p>Name service switch configuration file.</p></dd><dt><span class="term">/tmp/.winbindd/pipe</span></dt><dd><p>The UNIX pipe over which clients communicate with216 log file parameter.</p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id2532862"></a><h2>FILES</h2><div class="variablelist"><dl><dt><span class="term"><code class="filename">/etc/nsswitch.conf(5)</code></span></dt><dd><p>Name service switch configuration file.</p></dd><dt><span class="term">/tmp/.winbindd/pipe</span></dt><dd><p>The UNIX pipe over which clients communicate with 217 217 the <code class="literal">winbindd</code> program. For security reasons, the 218 218 winbind client will only attempt to connect to the winbindd daemon … … 235 235 This directory is by default <code class="filename">/usr/local/samba/var/locks 236 236 </code>. </p></dd><dt><span class="term">$LOCKDIR/winbindd_cache.tdb</span></dt><dd><p>Storage for cached user and group information. 237 </p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id25 26040"></a><h2>VERSION</h2><p>This man page is correct for version 3 of238 the Samba suite.</p></div><div class="refsect1" lang="en"><a name="id25 26051"></a><h2>SEE ALSO</h2><p><code class="filename">nsswitch.conf(5)</code>, <a class="citerefentry" href="samba.7.html"><span class="citerefentry"><span class="refentrytitle">samba</span>(7)</span></a>, <a class="citerefentry" href="wbinfo.1.html"><span class="citerefentry"><span class="refentrytitle">wbinfo</span>(1)</span></a>, <a class="citerefentry" href="ntlm_auth.8.html"><span class="citerefentry"><span class="refentrytitle">ntlm_auth</span>(8)</span></a>, <a class="citerefentry" href="smb.conf.5.html"><span class="citerefentry"><span class="refentrytitle">smb.conf</span>(5)</span></a>, <a class="citerefentry" href="pam_winbind.8.html"><span class="citerefentry"><span class="refentrytitle">pam_winbind</span>(8)</span></a></p></div><div class="refsect1" lang="en"><a name="id2526109"></a><h2>AUTHOR</h2><p>The original Samba software and related utilities237 </p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id2533008"></a><h2>VERSION</h2><p>This man page is correct for version 3 of 238 the Samba suite.</p></div><div class="refsect1" lang="en"><a name="id2533019"></a><h2>SEE ALSO</h2><p><code class="filename">nsswitch.conf(5)</code>, <a class="citerefentry" href="samba.7.html"><span class="citerefentry"><span class="refentrytitle">samba</span>(7)</span></a>, <a class="citerefentry" href="wbinfo.1.html"><span class="citerefentry"><span class="refentrytitle">wbinfo</span>(1)</span></a>, <a class="citerefentry" href="ntlm_auth.8.html"><span class="citerefentry"><span class="refentrytitle">ntlm_auth</span>(8)</span></a>, <a class="citerefentry" href="smb.conf.5.html"><span class="citerefentry"><span class="refentrytitle">smb.conf</span>(5)</span></a>, <a class="citerefentry" href="pam_winbind.8.html"><span class="citerefentry"><span class="refentrytitle">pam_winbind</span>(8)</span></a></p></div><div class="refsect1" lang="en"><a name="id2533074"></a><h2>AUTHOR</h2><p>The original Samba software and related utilities 239 239 were created by Andrew Tridgell. Samba is now developed 240 240 by the Samba Team as an Open Source project similar
Note:
See TracChangeset
for help on using the changeset viewer.