Ignore:
Timestamp:
Jun 24, 2009, 5:09:21 PM (16 years ago)
Author:
Herwig Bauernfeind
Message:

Update 3.0 to 3.0.35

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/samba-3.0/docs/manpages/ntlm_auth.1

    r158 r286  
    11.\"     Title: ntlm_auth
    2 .\"    Author:
    3 .\" Generator: DocBook XSL Stylesheets v1.73.2 <http://docbook.sf.net/>
    4 .\"      Date: 08/25/2008
     2.\"    Author: [see the "AUTHOR" section]
     3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
     4.\"      Date: 06/22/2009
    55.\"    Manual: User Commands
    66.\"    Source: Samba 3.0
     7.\"  Language: English
    78.\"
    8 .TH "NTLM_AUTH" "1" "08/25/2008" "Samba 3\.0" "User Commands"
     9.TH "NTLM_AUTH" "1" "06/22/2009" "Samba 3\&.0" "User Commands"
     10.\" -----------------------------------------------------------------
     11.\" * (re)Define some macros
     12.\" -----------------------------------------------------------------
     13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     14.\" toupper - uppercase a string (locale-aware)
     15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     16.de toupper
     17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
     18\\$*
     19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
     20..
     21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     22.\" SH-xref - format a cross-reference to an SH section
     23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     24.de SH-xref
     25.ie n \{\
     26.\}
     27.toupper \\$*
     28.el \{\
     29\\$*
     30.\}
     31..
     32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     33.\" SH - level-one heading that works better for non-TTY output
     34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     35.de1 SH
     36.\" put an extra blank line of space above the head in non-TTY output
     37.if t \{\
     38.sp 1
     39.\}
     40.sp \\n[PD]u
     41.nr an-level 1
     42.set-an-margin
     43.nr an-prevailing-indent \\n[IN]
     44.fi
     45.in \\n[an-margin]u
     46.ti 0
     47.HTML-TAG ".NH \\n[an-level]"
     48.it 1 an-trap
     49.nr an-no-space-flag 1
     50.nr an-break-flag 1
     51\." make the size of the head bigger
     52.ps +3
     53.ft B
     54.ne (2v + 1u)
     55.ie n \{\
     56.\" if n (TTY output), use uppercase
     57.toupper \\$*
     58.\}
     59.el \{\
     60.nr an-break-flag 0
     61.\" if not n (not TTY), use normal case (not uppercase)
     62\\$1
     63.in \\n[an-margin]u
     64.ti 0
     65.\" if not n (not TTY), put a border/line under subheading
     66.sp -.6
     67\l'\n(.lu'
     68.\}
     69..
     70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     71.\" SS - level-two heading that works better for non-TTY output
     72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     73.de1 SS
     74.sp \\n[PD]u
     75.nr an-level 1
     76.set-an-margin
     77.nr an-prevailing-indent \\n[IN]
     78.fi
     79.in \\n[IN]u
     80.ti \\n[SN]u
     81.it 1 an-trap
     82.nr an-no-space-flag 1
     83.nr an-break-flag 1
     84.ps \\n[PS-SS]u
     85\." make the size of the head bigger
     86.ps +2
     87.ft B
     88.ne (2v + 1u)
     89.if \\n[.$] \&\\$*
     90..
     91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     92.\" BB/BE - put background/screen (filled box) around block of text
     93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     94.de BB
     95.if t \{\
     96.sp -.5
     97.br
     98.in +2n
     99.ll -2n
     100.gcolor red
     101.di BX
     102.\}
     103..
     104.de EB
     105.if t \{\
     106.if "\\$2"adjust-for-leading-newline" \{\
     107.sp -1
     108.\}
     109.br
     110.di
     111.in
     112.ll
     113.gcolor
     114.nr BW \\n(.lu-\\n(.i
     115.nr BH \\n(dn+.5v
     116.ne \\n(BHu+.5v
     117.ie "\\$2"adjust-for-leading-newline" \{\
     118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
     119.\}
     120.el \{\
     121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
     122.\}
     123.in 0
     124.sp -.5v
     125.nf
     126.BX
     127.in
     128.sp .5v
     129.fi
     130.\}
     131..
     132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     133.\" BM/EM - put colored marker in margin next to block of text
     134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     135.de BM
     136.if t \{\
     137.br
     138.ll -2n
     139.gcolor red
     140.di BX
     141.\}
     142..
     143.de EM
     144.if t \{\
     145.br
     146.di
     147.ll
     148.gcolor
     149.nr BH \\n(dn
     150.ne \\n(BHu
     151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
     152.in 0
     153.nf
     154.BX
     155.in
     156.fi
     157.\}
     158..
     159.\" -----------------------------------------------------------------
     160.\" * set default formatting
     161.\" -----------------------------------------------------------------
    9162.\" disable hyphenation
    10163.nh
    11164.\" disable justification (adjust text to left margin only)
    12165.ad l
    13 .SH "NAME"
    14 ntlm_auth - tool to allow external access to Winbind's NTLM authentication function
    15 .SH "SYNOPSIS"
    16 .HP 1
    17 ntlm_auth [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>]
     166.\" -----------------------------------------------------------------
     167.\" * MAIN CONTENT STARTS HERE *
     168.\" -----------------------------------------------------------------
     169.SH "Name"
     170ntlm_auth \- tool to allow external access to Winbind\'s NTLM authentication function
     171.SH "Synopsis"
     172.fam C
     173.HP \w'\ 'u
     174\FCntlm_auth\F[] [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>]
     175.fam
    18176.SH "DESCRIPTION"
    19177.PP
    20178This tool is part of the
    21179\fBsamba\fR(7)
    22 suite\.
    23 .PP
    24 ntlm_auth
    25 is a helper utility that authenticates users using NT/LM authentication\. It returns 0 if the users is authenticated successfully and 1 if access was denied\. ntlm_auth uses winbind to access the user and authentication data for a domain\. This utility is only indended to be used by other programs (currently
     180suite\&.
     181.PP
     182\FCntlm_auth\F[]
     183is a helper utility that authenticates users using NT/LM authentication\&. It returns 0 if the users is authenticated successfully and 1 if access was denied\&. ntlm_auth uses winbind to access the user and authentication data for a domain\&. This utility is only indended to be used by other programs (currently
    26184Squid
    27185and
     
    31189The
    32190\fBwinbindd\fR(8)
    33 daemon must be operational for many of these commands to function\.
     191daemon must be operational for many of these commands to function\&.
    34192.PP
    35193Some of these commands also require access to the directory
    36 \fIwinbindd_privileged\fR
     194\FCwinbindd_privileged\F[]
    37195in
    38 \fI$LOCKDIR\fR\. This should be done either by running this command as root or providing group access to the
    39 \fIwinbindd_privileged\fR
    40 directory\. For security reasons, this directory should not be world\-accessable\.
     196\FC$LOCKDIR\F[]\&. This should be done either by running this command as root or providing group access to the
     197\FCwinbindd_privileged\F[]
     198directory\&. For security reasons, this directory should not be world\-accessable\&.
    41199.SH "OPTIONS"
    42200.PP
    43201\-\-helper\-protocol=PROTO
    44202.RS 4
    45 Operate as a stdio\-based helper\. Valid helper protocols are:
    46 .PP
    47 squid\-2\.4\-basic
    48 .RS 4
    49 Server\-side helper for use with Squid 2\.4\'s basic (plaintext) authentication\.
    50 .RE
    51 .PP
    52 squid\-2\.5\-basic
    53 .RS 4
    54 Server\-side helper for use with Squid 2\.5\'s basic (plaintext) authentication\.
    55 .RE
    56 .PP
    57 squid\-2\.5\-ntlmssp
    58 .RS 4
    59 Server\-side helper for use with Squid 2\.5\'s NTLMSSP authentication\.
     203Operate as a stdio\-based helper\&. Valid helper protocols are:
     204.PP
     205squid\-2\&.4\-basic
     206.RS 4
     207Server\-side helper for use with Squid 2\&.4\'s basic (plaintext) authentication\&.
     208.RE
     209.PP
     210squid\-2\&.5\-basic
     211.RS 4
     212Server\-side helper for use with Squid 2\&.5\'s basic (plaintext) authentication\&.
     213.RE
     214.PP
     215squid\-2\&.5\-ntlmssp
     216.RS 4
     217Server\-side helper for use with Squid 2\&.5\'s NTLMSSP authentication\&.
    60218.sp
    61219Requires access to the directory
    62 \fIwinbindd_privileged\fR
     220\FCwinbindd_privileged\F[]
    63221in
    64 \fI$LOCKDIR\fR\. The protocol used is described here:
    65 http://devel\.squid\-cache\.org/ntlm/squid_helper_protocol\.html\. This protocol has been extended to allow the NTLMSSP Negotiate packet to be included as an argument to the
    66 YR
    67 command\. (Thus avoiding loss of information in the protocol exchange)\.
     222\FC$LOCKDIR\F[]\&. The protocol used is described here:
     223http://devel\&.squid\-cache\&.org/ntlm/squid_helper_protocol\&.html\&. This protocol has been extended to allow the NTLMSSP Negotiate packet to be included as an argument to the
     224\FCYR\F[]
     225command\&. (Thus avoiding loss of information in the protocol exchange)\&.
    68226.RE
    69227.PP
    70228ntlmssp\-client\-1
    71229.RS 4
    72 Client\-side helper for use with arbitrary external programs that may wish to use Samba\'s NTLMSSP authentication knowledge\.
    73 .sp
    74 This helper is a client, and as such may be run by any user\. The protocol used is effectively the reverse of the previous protocol\. A
    75 YR
    76 command (without any arguments) starts the authentication exchange\.
     230Client\-side helper for use with arbitrary external programs that may wish to use Samba\'s NTLMSSP authentication knowledge\&.
     231.sp
     232This helper is a client, and as such may be run by any user\&. The protocol used is effectively the reverse of the previous protocol\&. A
     233\FCYR\F[]
     234command (without any arguments) starts the authentication exchange\&.
    77235.RE
    78236.PP
    79237gss\-spnego
    80238.RS 4
    81 Server\-side helper that implements GSS\-SPNEGO\. This uses a protocol that is almost the same as
    82 squid\-2\.5\-ntlmssp, but has some subtle differences that are undocumented outside the source at this stage\.
     239Server\-side helper that implements GSS\-SPNEGO\&. This uses a protocol that is almost the same as
     240\FCsquid\-2\&.5\-ntlmssp\F[], but has some subtle differences that are undocumented outside the source at this stage\&.
    83241.sp
    84242Requires access to the directory
    85 \fIwinbindd_privileged\fR
     243\FCwinbindd_privileged\F[]
    86244in
    87 \fI$LOCKDIR\fR\.
     245\FC$LOCKDIR\F[]\&.
    88246.RE
    89247.PP
    90248gss\-spnego\-client
    91249.RS 4
    92 Client\-side helper that implements GSS\-SPNEGO\. This also uses a protocol similar to the above helpers, but is currently undocumented\.
     250Client\-side helper that implements GSS\-SPNEGO\&. This also uses a protocol similar to the above helpers, but is currently undocumented\&.
    93251.RE
    94252.PP
    95253ntlm\-server\-1
    96254.RS 4
    97 Server\-side helper protocol, intended for use by a RADIUS server or the \'winbind\' plugin for pppd, for the provision of MSCHAP and MSCHAPv2 authentication\.
     255Server\-side helper protocol, intended for use by a RADIUS server or the \'winbind\' plugin for pppd, for the provision of MSCHAP and MSCHAPv2 authentication\&.
    98256.sp
    99257This protocol consists of lines in the form:
    100 Parameter: value
     258\FCParameter: value\F[]
    101259and
    102 Parameter:: Base64\-encode value\. The presence of a single period
    103 \.
    104 indicates that one side has finished supplying data to the other\. (Which in turn could cause the helper to authenticate the user)\.
     260\FCParameter:: Base64\-encode value\F[]\&. The presence of a single period
     261\FC\&.\F[]
     262indicates that one side has finished supplying data to the other\&. (Which in turn could cause the helper to authenticate the user)\&.
    105263.sp
    106264Curently implemented parameters from the external program to the helper are:
     
    109267.RS 4
    110268The username, expected to be in Samba\'s
    111 \fIunix charset\fR\.
    112 .PP \fBExample\ 1.\ \fR Username: bob
    113 .PP \fBExample\ 2.\ \fR Username:: Ym9i
     269\m[blue]\fBunix charset\fR\m[]\&.
     270.PP \fBExample\ \&1.\ \&\fR Username: bob
     271.PP \fBExample\ \&2.\ \&\fR Username:: Ym9i
    114272.RE
    115273.PP
     
    117275.RS 4
    118276The user\'s domain, expected to be in Samba\'s
    119 \fIunix charset\fR\.
    120 .PP \fBExample\ 3.\ \fR Domain: WORKGROUP
    121 .PP \fBExample\ 4.\ \fR Domain:: V09SS0dST1VQ
     277\m[blue]\fBunix charset\fR\m[]\&.
     278.PP \fBExample\ \&3.\ \&\fR Domain: WORKGROUP
     279.PP \fBExample\ \&4.\ \&\fR Domain:: V09SS0dST1VQ
    122280.RE
    123281.PP
     
    125283.RS 4
    126284The fully qualified username, expected to be in Samba\'s
    127 \fIunix charset\fR
     285\m[blue]\fBunix charset\fR\m[]
    128286and qualified with the
    129 \fIwinbind separator\fR\.
    130 .PP \fBExample\ 5.\ \fR Full\-Username: WORKGROUP\ebob
    131 .PP \fBExample\ 6.\ \fR Full\-Username:: V09SS0dST1VQYm9i
     287\m[blue]\fBwinbind separator\fR\m[]\&.
     288.PP \fBExample\ \&5.\ \&\fR Full\-Username: WORKGROUP\ebob
     289.PP \fBExample\ \&6.\ \&\fR Full\-Username:: V09SS0dST1VQYm9i
    132290.RE
    133291.PP
     
    135293.RS 4
    136294The 8 byte
    137 LANMAN Challenge
    138 value, generated randomly by the server, or (in cases such as MSCHAPv2) generated in some way by both the server and the client\.
    139 .PP \fBExample\ 7.\ \fR LANMAN\-Challege: 0102030405060708
     295\FCLANMAN Challenge\F[]
     296value, generated randomly by the server, or (in cases such as MSCHAPv2) generated in some way by both the server and the client\&.
     297.PP \fBExample\ \&7.\ \&\fR LANMAN\-Challege: 0102030405060708
    140298.RE
    141299.PP
     
    143301.RS 4
    144302The 24 byte
    145 LANMAN Response
     303\FCLANMAN Response\F[]
    146304value, calculated from the user\'s password and the supplied
    147 LANMAN Challenge\. Typically, this is provided over the network by a client wishing to authenticate\.
    148 .PP \fBExample\ 8.\ \fR LANMAN\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
     305\FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&.
     306.PP \fBExample\ \&8.\ \&\fR LANMAN\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
    149307.RE
    150308.PP
     
    152310.RS 4
    153311The >= 24 byte
    154 NT Response
     312\FCNT Response\F[]
    155313calculated from the user\'s password and the supplied
    156 LANMAN Challenge\. Typically, this is provided over the network by a client wishing to authenticate\.
    157 .PP \fBExample\ 9.\ \fR NT\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
     314\FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&.
     315.PP \fBExample\ \&9.\ \&\fR NT\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
    158316.RE
    159317.PP
    160318Password
    161319.RS 4
    162 The user\'s password\. This would be provided by a network client, if the helper is being used in a legacy situation that exposes plaintext passwords in this way\.
    163 .PP \fBExample\ 10.\ \fR Password: samba2
    164 .PP \fBExample\ 11.\ \fR Password:: c2FtYmEy
     320The user\'s password\&. This would be provided by a network client, if the helper is being used in a legacy situation that exposes plaintext passwords in this way\&.
     321.PP \fBExample\ \&10.\ \&\fR Password: samba2
     322.PP \fBExample\ \&11.\ \&\fR Password:: c2FtYmEy
    165323.RE
    166324.PP
    167325Request\-User\-Session\-Key
    168326.RS 4
    169 Apon sucessful authenticaiton, return the user session key associated with the login\.
    170 .PP \fBExample\ 12.\ \fR Request\-User\-Session\-Key: Yes
     327Apon sucessful authenticaiton, return the user session key associated with the login\&.
     328.PP \fBExample\ \&12.\ \&\fR Request\-User\-Session\-Key: Yes
    171329.RE
    172330.PP
    173331Request\-LanMan\-Session\-Key
    174332.RS 4
    175 Apon sucessful authenticaiton, return the LANMAN session key associated with the login\.
    176 .PP \fBExample\ 13.\ \fR Request\-LanMan\-Session\-Key: Yes
    177 .RE
    178 .sp
     333Apon sucessful authenticaiton, return the LANMAN session key associated with the login\&.
     334.PP \fBExample\ \&13.\ \&\fR Request\-LanMan\-Session\-Key: Yes
     335.RE
     336.if n \{\
     337.sp
     338.\}
     339.RS 4
     340.BM yellow
    179341.it 1 an-trap
    180342.nr an-no-space-flag 1
    181343.nr an-break-flag 1
    182344.br
    183 Warning
     345.ps +1
     346\fBWarning\fR
     347.ps -1
     348.br
    184349Implementors should take care to base64 encode
    185350                any data (such as usernames/passwords) that may contain malicous user data, such as
    186                 a newline\.  They may also need to decode strings from
    187                 the helper, which likewise may have been base64 encoded\.
     351                a newline\&.  They may also need to decode strings from
     352                the helper, which likewise may have been base64 encoded\&..sp .5v
     353.EM yellow
     354.RE
    188355.RE
    189356.RE
     
    223390User\'s plaintext password
    224391.sp
    225 If not specified on the command line, this is prompted for when required\.
    226 .sp
    227 For the NTLMSSP based server roles, this parameter specifies the expected password, allowing testing without winbindd operational\.
     392If not specified on the command line, this is prompted for when required\&.
     393.sp
     394For the NTLMSSP based server roles, this parameter specifies the expected password, allowing testing without winbindd operational\&.
    228395.RE
    229396.PP
     
    240407\-\-diagnostics
    241408.RS 4
    242 Perform Diagnostics on the authentication chain\. Uses the password from
    243 \-\-password
    244 or prompts for one\.
     409Perform Diagnostics on the authentication chain\&. Uses the password from
     410\FC\-\-password\F[]
     411or prompts for one\&.
    245412.RE
    246413.PP
    247414\-\-require\-membership\-of={SID|Name}
    248415.RS 4
    249 Require that a user be a member of specified group (either name or SID) for authentication to succeed\.
     416Require that a user be a member of specified group (either name or SID) for authentication to succeed\&.
    250417.RE
    251418.PP
     
    253420.RS 4
    254421\fIlevel\fR
    255 is an integer from 0 to 10\. The default value if this parameter is not specified is 0\.
    256 .sp
    257 The higher this value, the more detail will be logged to the log files about the activities of the server\. At level 0, only critical errors and serious warnings will be logged\. Level 1 is a reasonable level for day\-to\-day running \- it generates a small amount of information about operations carried out\.
    258 .sp
    259 Levels above 1 will generate considerable amounts of log data, and should only be used when investigating a problem\. Levels above 3 are designed for use only by developers and generate HUGE amounts of log data, most of which is extremely cryptic\.
     422is an integer from 0 to 10\&. The default value if this parameter is not specified is 0\&.
     423.sp
     424The higher this value, the more detail will be logged to the log files about the activities of the server\&. At level 0, only critical errors and serious warnings will be logged\&. Level 1 is a reasonable level for day\-to\-day running \- it generates a small amount of information about operations carried out\&.
     425.sp
     426Levels above 1 will generate considerable amounts of log data, and should only be used when investigating a problem\&. Levels above 3 are designed for use only by developers and generate HUGE amounts of log data, most of which is extremely cryptic\&.
    260427.sp
    261428Note that specifying this parameter here will override the
    262 \fIlog level\fR
     429\m[blue]\fBlog level\fR\m[]
    263430parameter in the
    264 \fIsmb\.conf\fR
    265 file\.
     431\FCsmb\&.conf\F[]
     432file\&.
    266433.RE
    267434.PP
    268435\-V
    269436.RS 4
    270 Prints the program version number\.
     437Prints the program version number\&.
    271438.RE
    272439.PP
    273440\-s <configuration file>
    274441.RS 4
    275 The file specified contains the configuration details required by the server\. The information in this file includes server\-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide\. See
    276 \fIsmb\.conf\fR
    277 for more information\. The default configuration file name is determined at compile time\.
     442The file specified contains the configuration details required by the server\&. The information in this file includes server\-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide\&. See
     443\FCsmb\&.conf\F[]
     444for more information\&. The default configuration file name is determined at compile time\&.
    278445.RE
    279446.PP
    280447\-l|\-\-log\-basename=logdirectory
    281448.RS 4
    282 Base directory name for log/debug files\. The extension
    283 \fB"\.progname"\fR
    284 will be appended (e\.g\. log\.smbclient, log\.smbd, etc\.\.\.)\. The log file is never removed by the client\.
     449Base directory name for log/debug files\&. The extension
     450\fB"\&.progname"\fR
     451will be appended (e\&.g\&. log\&.smbclient, log\&.smbd, etc\&.\&.\&.)\&. The log file is never removed by the client\&.
    285452.RE
    286453.PP
    287454\-h|\-\-help
    288455.RS 4
    289 Print a summary of command line options\.
     456Print a summary of command line options\&.
    290457.RE
    291458.SH "EXAMPLE SETUP"
    292459.PP
    293 To setup ntlm_auth for use by squid 2\.5, with both basic and NTLMSSP authentication, the following should be placed in the
    294 \fIsquid\.conf\fR
    295 file\.
    296 .sp
    297 .RS 4
     460To setup ntlm_auth for use by squid 2\&.5, with both basic and NTLMSSP authentication, the following should be placed in the
     461\FCsquid\&.conf\F[]
     462file\&.
     463.sp
     464.if n \{\
     465.RS 4
     466.\}
     467.fam C
     468.ps -1
    298469.nf
    299 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-ntlmssp
    300 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-basic
     470.if t \{\
     471.sp -1
     472.\}
     473.BB lightgray adjust-for-leading-newline
     474.sp -1
     475
     476auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp
     477auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic
    301478auth_param basic children 5
    302479auth_param basic realm Squid proxy\-caching web server
    303480auth_param basic credentialsttl 2 hours
     481.EB lightgray adjust-for-leading-newline
     482.if t \{\
     483.sp 1
     484.\}
    304485.fi
    305 .RE
    306 .sp
     486.fam
     487.ps +1
     488.if n \{\
     489.RE
     490.\}
     491.if n \{\
     492.sp
     493.\}
     494.RS 4
     495.BM yellow
    307496.it 1 an-trap
    308497.nr an-no-space-flag 1
    309498.nr an-break-flag 1
    310499.br
    311 Note
     500.ps +1
     501\fBNote\fR
     502.ps -1
     503.br
    312504.PP
    313505This example assumes that ntlm_auth has been installed into your path, and that the group permissions on
    314 \fIwinbindd_privileged\fR
    315 are as described above\.
    316 .PP
    317 To setup ntlm_auth for use by squid 2\.5 with group limitation in addition to the above example, the following should be added to the
    318 \fIsquid\.conf\fR
    319 file\.
    320 .sp
    321 .RS 4
     506\FCwinbindd_privileged\F[]
     507are as described above\&.
     508.sp .5v
     509.EM yellow
     510.RE
     511.PP
     512To setup ntlm_auth for use by squid 2\&.5 with group limitation in addition to the above example, the following should be added to the
     513\FCsquid\&.conf\F[]
     514file\&.
     515.sp
     516.if n \{\
     517.RS 4
     518.\}
     519.fam C
     520.ps -1
    322521.nf
    323 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-ntlmssp \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
    324 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-basic \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
     522.if t \{\
     523.sp -1
     524.\}
     525.BB lightgray adjust-for-leading-newline
     526.sp -1
     527
     528auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
     529auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
     530.EB lightgray adjust-for-leading-newline
     531.if t \{\
     532.sp 1
     533.\}
    325534.fi
    326 .RE
     535.fam
     536.ps +1
     537.if n \{\
     538.RE
     539.\}
    327540.SH "TROUBLESHOOTING"
    328541.PP
    329 If you\'re experiencing problems with authenticating Internet Explorer running under MS Windows 9X or Millenium Edition against ntlm_auth\'s NTLMSSP authentication helper (\-\-helper\-protocol=squid\-2\.5\-ntlmssp), then please read
    330 the Microsoft Knowledge Base article #239869 and follow instructions described there\.
     542If you\'re experiencing problems with authenticating Internet Explorer running under MS Windows 9X or Millenium Edition against ntlm_auth\'s NTLMSSP authentication helper (\-\-helper\-protocol=squid\-2\&.5\-ntlmssp), then please read
     543the Microsoft Knowledge Base article #239869 and follow instructions described there\&.
    331544.SH "VERSION"
    332545.PP
    333 This man page is correct for version 3\.0 of the Samba suite\.
     546This man page is correct for version 3\&.0 of the Samba suite\&.
    334547.SH "AUTHOR"
    335548.PP
    336 The original Samba software and related utilities were created by Andrew Tridgell\. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\.
    337 .PP
    338 The ntlm_auth manpage was written by Jelmer Vernooij and Andrew Bartlett\.
     549The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&.
     550.PP
     551The ntlm_auth manpage was written by Jelmer Vernooij and Andrew Bartlett\&.
Note: See TracChangeset for help on using the changeset viewer.