Ignore:
Timestamp:
May 27, 2009, 9:08:03 AM (16 years ago)
Author:
Herwig Bauernfeind
Message:

Update 3.2 branch to 3.2.8 docs

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/samba-3.2.x/docs/manpages/pam_winbind.7

    r229 r231  
    11.\"     Title: pam_winbind
    2 .\"    Author:
    3 .\" Generator: DocBook XSL Stylesheets v1.73.1 <http://docbook.sf.net/>
    4 .\"      Date: 12/19/2008
     2.\"    Author: [see the "AUTHOR" section]
     3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
     4.\"      Date: 02/03/2009
    55.\"    Manual: 7
    66.\"    Source: Samba 3.2
     7.\"  Language: English
    78.\"
    8 .TH "PAM_WINBIND" "7" "12/19/2008" "Samba 3\.2" "7"
     9.TH "PAM_WINBIND" "7" "02/03/2009" "Samba 3\&.2" "7"
     10.\" -----------------------------------------------------------------
     11.\" * (re)Define some macros
     12.\" -----------------------------------------------------------------
     13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     14.\" toupper - uppercase a string (locale-aware)
     15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     16.de toupper
     17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
     18\\$*
     19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
     20..
     21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     22.\" SH-xref - format a cross-reference to an SH section
     23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     24.de SH-xref
     25.ie n \{\
     26.\}
     27.toupper \\$*
     28.el \{\
     29\\$*
     30.\}
     31..
     32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     33.\" SH - level-one heading that works better for non-TTY output
     34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     35.de1 SH
     36.\" put an extra blank line of space above the head in non-TTY output
     37.if t \{\
     38.sp 1
     39.\}
     40.sp \\n[PD]u
     41.nr an-level 1
     42.set-an-margin
     43.nr an-prevailing-indent \\n[IN]
     44.fi
     45.in \\n[an-margin]u
     46.ti 0
     47.HTML-TAG ".NH \\n[an-level]"
     48.it 1 an-trap
     49.nr an-no-space-flag 1
     50.nr an-break-flag 1
     51\." make the size of the head bigger
     52.ps +3
     53.ft B
     54.ne (2v + 1u)
     55.ie n \{\
     56.\" if n (TTY output), use uppercase
     57.toupper \\$*
     58.\}
     59.el \{\
     60.nr an-break-flag 0
     61.\" if not n (not TTY), use normal case (not uppercase)
     62\\$1
     63.in \\n[an-margin]u
     64.ti 0
     65.\" if not n (not TTY), put a border/line under subheading
     66.sp -.6
     67\l'\n(.lu'
     68.\}
     69..
     70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     71.\" SS - level-two heading that works better for non-TTY output
     72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     73.de1 SS
     74.sp \\n[PD]u
     75.nr an-level 1
     76.set-an-margin
     77.nr an-prevailing-indent \\n[IN]
     78.fi
     79.in \\n[IN]u
     80.ti \\n[SN]u
     81.it 1 an-trap
     82.nr an-no-space-flag 1
     83.nr an-break-flag 1
     84.ps \\n[PS-SS]u
     85\." make the size of the head bigger
     86.ps +2
     87.ft B
     88.ne (2v + 1u)
     89.if \\n[.$] \&\\$*
     90..
     91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     92.\" BB/BE - put background/screen (filled box) around block of text
     93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     94.de BB
     95.if t \{\
     96.sp -.5
     97.br
     98.in +2n
     99.ll -2n
     100.gcolor red
     101.di BX
     102.\}
     103..
     104.de EB
     105.if t \{\
     106.if "\\$2"adjust-for-leading-newline" \{\
     107.sp -1
     108.\}
     109.br
     110.di
     111.in
     112.ll
     113.gcolor
     114.nr BW \\n(.lu-\\n(.i
     115.nr BH \\n(dn+.5v
     116.ne \\n(BHu+.5v
     117.ie "\\$2"adjust-for-leading-newline" \{\
     118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
     119.\}
     120.el \{\
     121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
     122.\}
     123.in 0
     124.sp -.5v
     125.nf
     126.BX
     127.in
     128.sp .5v
     129.fi
     130.\}
     131..
     132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     133.\" BM/EM - put colored marker in margin next to block of text
     134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     135.de BM
     136.if t \{\
     137.br
     138.ll -2n
     139.gcolor red
     140.di BX
     141.\}
     142..
     143.de EM
     144.if t \{\
     145.br
     146.di
     147.ll
     148.gcolor
     149.nr BH \\n(dn
     150.ne \\n(BHu
     151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
     152.in 0
     153.nf
     154.BX
     155.in
     156.fi
     157.\}
     158..
     159.\" -----------------------------------------------------------------
     160.\" * set default formatting
     161.\" -----------------------------------------------------------------
    9162.\" disable hyphenation
    10163.nh
    11164.\" disable justification (adjust text to left margin only)
    12165.ad l
    13 .SH "NAME"
    14 pam_winbind - PAM module for Winbind
     166.\" -----------------------------------------------------------------
     167.\" * MAIN CONTENT STARTS HERE *
     168.\" -----------------------------------------------------------------
     169.SH "Name"
     170pam_winbind \- PAM module for Winbind
    15171.SH "DESCRIPTION"
    16172.PP
    17173This tool is part of the
    18174\fBsamba\fR(7)
    19 suite\.
    20 .PP
    21 pam_winbind is a PAM module that can authenticate users against the local domain by talking to the Winbind daemon\.
     175suite\&.
     176.PP
     177pam_winbind is a PAM module that can authenticate users against the local domain by talking to the Winbind daemon\&.
    22178.SH "OPTIONS"
    23179.PP
    24180pam_winbind supports several options which can either be set in the PAM configuration files or in the pam_winbind configuration file situated at
    25 \fI/etc/security/pam_winbind\.conf\fR\. Options from the PAM configuration file take precedence to those from the configuration file\.
     181\FC/etc/security/pam_winbind\&.conf\F[]\&. Options from the PAM configuration file take precedence to those from the configuration file\&.
    26182.PP
    27183debug
    28184.RS 4
    29 Gives debugging output to syslog\.
     185Gives debugging output to syslog\&.
    30186.RE
    31187.PP
    32188debug_state
    33189.RS 4
    34 Gives detailed PAM state debugging output to syslog\.
     190Gives detailed PAM state debugging output to syslog\&.
    35191.RE
    36192.PP
    37193require_membership_of=[SID or NAME]
    38194.RS 4
    39 If this option is set, pam_winbind will only succeed if the user is a member of the given SID or NAME\. A SID can be either a group\-SID, an alias\-SID or even an user\-SID\. It is also possible to give a NAME instead of the SID\. That name must have the form:
     195If this option is set, pam_winbind will only succeed if the user is a member of the given SID or NAME\&. A SID can be either a group\-SID, an alias\-SID or even an user\-SID\&. It is also possible to give a NAME instead of the SID\&. That name must have the form:
    40196\fIMYDOMAIN\e\emygroup\fR
    41197or
    42 \fIMYDOMAIN\e\emyuser\fR\. pam_winbind will, in that case, lookup the SID internally\. Note that NAME may not contain any spaces\. It is thus recommended to only use SIDs\. You can verify the list of SIDs a user is a member of with
    43 wbinfo \-\-user\-sids=SID\.
     198\fIMYDOMAIN\e\emyuser\fR\&. pam_winbind will, in that case, lookup the SID internally\&. Note that NAME may not contain any spaces\&. It is thus recommended to only use SIDs\&. You can verify the list of SIDs a user is a member of with
     199\FCwbinfo \-\-user\-sids=SID\F[]\&.
    44200.RE
    45201.PP
     
    50206use_first_pass
    51207.RS 4
    52 By default, pam_winbind tries to get the authentication token from a previous module\. If no token is available it asks the user for the old password\. With this option, pam_winbind aborts with an error if no authentication token from a previous module is available\.
     208By default, pam_winbind tries to get the authentication token from a previous module\&. If no token is available it asks the user for the old password\&. With this option, pam_winbind aborts with an error if no authentication token from a previous module is available\&.
    53209.RE
    54210.PP
    55211use_authtok
    56212.RS 4
    57 Set the new password to the one provided by the previously stacked password module\. If this option is not set pam_winbind will ask the user for the new password\.
     213Set the new password to the one provided by the previously stacked password module\&. If this option is not set pam_winbind will ask the user for the new password\&.
    58214.RE
    59215.PP
    60216krb5_auth
    61217.RS 4
    62 pam_winbind can authenticate using Kerberos when winbindd is talking to an Active Directory domain controller\. Kerberos authentication must be enabled with this parameter\. When Kerberos authentication can not succeed (e\.g\. due to clock skew), winbindd will fallback to samlogon authentication over MSRPC\. When this parameter is used in conjunction with
    63 \fIwinbind refresh tickets\fR, winbind will keep your Ticket Granting Ticket (TGT) uptodate by refreshing it whenever necessary\.
     218pam_winbind can authenticate using Kerberos when winbindd is talking to an Active Directory domain controller\&. Kerberos authentication must be enabled with this parameter\&. When Kerberos authentication can not succeed (e\&.g\&. due to clock skew), winbindd will fallback to samlogon authentication over MSRPC\&. When this parameter is used in conjunction with
     219\fIwinbind refresh tickets\fR, winbind will keep your Ticket Granting Ticket (TGT) uptodate by refreshing it whenever necessary\&.
    64220.RE
    65221.PP
     
    68224When pam_winbind is configured to try kerberos authentication by enabling the
    69225\fIkrb5_auth\fR
    70 option, it can store the retrieved Ticket Granting Ticket (TGT) in a credential cache\. The type of credential cache can be set with this option\. Currently the only supported value is:
    71 \fIFILE\fR\. In that case a credential cache in the form of /tmp/krb5cc_UID will be created, where UID is replaced with the numeric user id\. Leave empty to just do kerberos authentication without having a ticket cache after the logon has succeeded\.
     226option, it can store the retrieved Ticket Granting Ticket (TGT) in a credential cache\&. The type of credential cache can be set with this option\&. Currently the only supported value is:
     227\fIFILE\fR\&. In that case a credential cache in the form of /tmp/krb5cc_UID will be created, where UID is replaced with the numeric user id\&. Leave empty to just do kerberos authentication without having a ticket cache after the logon has succeeded\&.
    72228.RE
    73229.PP
     
    76232Winbind allows to logon using cached credentials when
    77233\fIwinbind offline logon\fR
    78 is enabled\. To use this feature from the PAM module this option must be set\.
     234is enabled\&. To use this feature from the PAM module this option must be set\&.
    79235.RE
    80236.PP
    81237silent
    82238.RS 4
    83 Do not emit any messages\.
     239Do not emit any messages\&.
    84240.RE
    85241.SH "SEE ALSO"
     
    90246.SH "VERSION"
    91247.PP
    92 This man page is correct for version 3 of Samba\.
     248This man page is correct for version 3 of Samba\&.
    93249.SH "AUTHOR"
    94250.PP
    95 The original Samba software and related utilities were created by Andrew Tridgell\. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\.
    96 .PP
    97 This manpage was written by Jelmer Vernooij and Guenther Deschner\.
     251The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&.
     252.PP
     253This manpage was written by Jelmer Vernooij and Guenther Deschner\&.
Note: See TracChangeset for help on using the changeset viewer.