Changeset 286 for branches/samba-3.0/docs/manpages/ntlm_auth.1
- Timestamp:
- Jun 24, 2009, 5:09:21 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.0/docs/manpages/ntlm_auth.1
r158 r286 1 1 .\" Title: ntlm_auth 2 .\" Author: 3 .\" Generator: DocBook XSL Stylesheets v1.7 3.2<http://docbook.sf.net/>4 .\" Date: 0 8/25/20082 .\" Author: [see the "AUTHOR" section] 3 .\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/> 4 .\" Date: 06/22/2009 5 5 .\" Manual: User Commands 6 6 .\" Source: Samba 3.0 7 .\" Language: English 7 8 .\" 8 .TH "NTLM_AUTH" "1" "08/25/2008" "Samba 3\.0" "User Commands" 9 .TH "NTLM_AUTH" "1" "06/22/2009" "Samba 3\&.0" "User Commands" 10 .\" ----------------------------------------------------------------- 11 .\" * (re)Define some macros 12 .\" ----------------------------------------------------------------- 13 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 14 .\" toupper - uppercase a string (locale-aware) 15 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 16 .de toupper 17 .tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ 18 \\$* 19 .tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz 20 .. 21 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 22 .\" SH-xref - format a cross-reference to an SH section 23 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 24 .de SH-xref 25 .ie n \{\ 26 .\} 27 .toupper \\$* 28 .el \{\ 29 \\$* 30 .\} 31 .. 32 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 33 .\" SH - level-one heading that works better for non-TTY output 34 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 35 .de1 SH 36 .\" put an extra blank line of space above the head in non-TTY output 37 .if t \{\ 38 .sp 1 39 .\} 40 .sp \\n[PD]u 41 .nr an-level 1 42 .set-an-margin 43 .nr an-prevailing-indent \\n[IN] 44 .fi 45 .in \\n[an-margin]u 46 .ti 0 47 .HTML-TAG ".NH \\n[an-level]" 48 .it 1 an-trap 49 .nr an-no-space-flag 1 50 .nr an-break-flag 1 51 \." make the size of the head bigger 52 .ps +3 53 .ft B 54 .ne (2v + 1u) 55 .ie n \{\ 56 .\" if n (TTY output), use uppercase 57 .toupper \\$* 58 .\} 59 .el \{\ 60 .nr an-break-flag 0 61 .\" if not n (not TTY), use normal case (not uppercase) 62 \\$1 63 .in \\n[an-margin]u 64 .ti 0 65 .\" if not n (not TTY), put a border/line under subheading 66 .sp -.6 67 \l'\n(.lu' 68 .\} 69 .. 70 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 71 .\" SS - level-two heading that works better for non-TTY output 72 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 73 .de1 SS 74 .sp \\n[PD]u 75 .nr an-level 1 76 .set-an-margin 77 .nr an-prevailing-indent \\n[IN] 78 .fi 79 .in \\n[IN]u 80 .ti \\n[SN]u 81 .it 1 an-trap 82 .nr an-no-space-flag 1 83 .nr an-break-flag 1 84 .ps \\n[PS-SS]u 85 \." make the size of the head bigger 86 .ps +2 87 .ft B 88 .ne (2v + 1u) 89 .if \\n[.$] \&\\$* 90 .. 91 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 92 .\" BB/BE - put background/screen (filled box) around block of text 93 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 94 .de BB 95 .if t \{\ 96 .sp -.5 97 .br 98 .in +2n 99 .ll -2n 100 .gcolor red 101 .di BX 102 .\} 103 .. 104 .de EB 105 .if t \{\ 106 .if "\\$2"adjust-for-leading-newline" \{\ 107 .sp -1 108 .\} 109 .br 110 .di 111 .in 112 .ll 113 .gcolor 114 .nr BW \\n(.lu-\\n(.i 115 .nr BH \\n(dn+.5v 116 .ne \\n(BHu+.5v 117 .ie "\\$2"adjust-for-leading-newline" \{\ 118 \M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 119 .\} 120 .el \{\ 121 \M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 122 .\} 123 .in 0 124 .sp -.5v 125 .nf 126 .BX 127 .in 128 .sp .5v 129 .fi 130 .\} 131 .. 132 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 133 .\" BM/EM - put colored marker in margin next to block of text 134 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 135 .de BM 136 .if t \{\ 137 .br 138 .ll -2n 139 .gcolor red 140 .di BX 141 .\} 142 .. 143 .de EM 144 .if t \{\ 145 .br 146 .di 147 .ll 148 .gcolor 149 .nr BH \\n(dn 150 .ne \\n(BHu 151 \M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[] 152 .in 0 153 .nf 154 .BX 155 .in 156 .fi 157 .\} 158 .. 159 .\" ----------------------------------------------------------------- 160 .\" * set default formatting 161 .\" ----------------------------------------------------------------- 9 162 .\" disable hyphenation 10 163 .nh 11 164 .\" disable justification (adjust text to left margin only) 12 165 .ad l 13 .SH "NAME" 14 ntlm_auth - tool to allow external access to Winbind's NTLM authentication function 15 .SH "SYNOPSIS" 16 .HP 1 17 ntlm_auth [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>] 166 .\" ----------------------------------------------------------------- 167 .\" * MAIN CONTENT STARTS HERE * 168 .\" ----------------------------------------------------------------- 169 .SH "Name" 170 ntlm_auth \- tool to allow external access to Winbind\'s NTLM authentication function 171 .SH "Synopsis" 172 .fam C 173 .HP \w'\ 'u 174 \FCntlm_auth\F[] [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>] 175 .fam 18 176 .SH "DESCRIPTION" 19 177 .PP 20 178 This tool is part of the 21 179 \fBsamba\fR(7) 22 suite\ .23 .PP 24 ntlm_auth 25 is a helper utility that authenticates users using NT/LM authentication\ . It returns 0 if the users is authenticated successfully and 1 if access was denied\. ntlm_auth uses winbind to access the user and authentication data for a domain\. This utility is only indended to be used by other programs (currently180 suite\&. 181 .PP 182 \FCntlm_auth\F[] 183 is a helper utility that authenticates users using NT/LM authentication\&. It returns 0 if the users is authenticated successfully and 1 if access was denied\&. ntlm_auth uses winbind to access the user and authentication data for a domain\&. This utility is only indended to be used by other programs (currently 26 184 Squid 27 185 and … … 31 189 The 32 190 \fBwinbindd\fR(8) 33 daemon must be operational for many of these commands to function\ .191 daemon must be operational for many of these commands to function\&. 34 192 .PP 35 193 Some of these commands also require access to the directory 36 \ fIwinbindd_privileged\fR194 \FCwinbindd_privileged\F[] 37 195 in 38 \ fI$LOCKDIR\fR\. This should be done either by running this command as root or providing group access to the39 \ fIwinbindd_privileged\fR40 directory\ . For security reasons, this directory should not be world\-accessable\.196 \FC$LOCKDIR\F[]\&. This should be done either by running this command as root or providing group access to the 197 \FCwinbindd_privileged\F[] 198 directory\&. For security reasons, this directory should not be world\-accessable\&. 41 199 .SH "OPTIONS" 42 200 .PP 43 201 \-\-helper\-protocol=PROTO 44 202 .RS 4 45 Operate as a stdio\-based helper\ . Valid helper protocols are:46 .PP 47 squid\-2\ .4\-basic48 .RS 4 49 Server\-side helper for use with Squid 2\ .4\'s basic (plaintext) authentication\.50 .RE 51 .PP 52 squid\-2\ .5\-basic53 .RS 4 54 Server\-side helper for use with Squid 2\ .5\'s basic (plaintext) authentication\.55 .RE 56 .PP 57 squid\-2\ .5\-ntlmssp58 .RS 4 59 Server\-side helper for use with Squid 2\ .5\'s NTLMSSP authentication\.203 Operate as a stdio\-based helper\&. Valid helper protocols are: 204 .PP 205 squid\-2\&.4\-basic 206 .RS 4 207 Server\-side helper for use with Squid 2\&.4\'s basic (plaintext) authentication\&. 208 .RE 209 .PP 210 squid\-2\&.5\-basic 211 .RS 4 212 Server\-side helper for use with Squid 2\&.5\'s basic (plaintext) authentication\&. 213 .RE 214 .PP 215 squid\-2\&.5\-ntlmssp 216 .RS 4 217 Server\-side helper for use with Squid 2\&.5\'s NTLMSSP authentication\&. 60 218 .sp 61 219 Requires access to the directory 62 \ fIwinbindd_privileged\fR220 \FCwinbindd_privileged\F[] 63 221 in 64 \ fI$LOCKDIR\fR\. The protocol used is described here:65 http://devel\ .squid\-cache\.org/ntlm/squid_helper_protocol\.html\. This protocol has been extended to allow the NTLMSSP Negotiate packet to be included as an argument to the66 YR 67 command\ . (Thus avoiding loss of information in the protocol exchange)\.222 \FC$LOCKDIR\F[]\&. The protocol used is described here: 223 http://devel\&.squid\-cache\&.org/ntlm/squid_helper_protocol\&.html\&. This protocol has been extended to allow the NTLMSSP Negotiate packet to be included as an argument to the 224 \FCYR\F[] 225 command\&. (Thus avoiding loss of information in the protocol exchange)\&. 68 226 .RE 69 227 .PP 70 228 ntlmssp\-client\-1 71 229 .RS 4 72 Client\-side helper for use with arbitrary external programs that may wish to use Samba\'s NTLMSSP authentication knowledge\ .73 .sp 74 This helper is a client, and as such may be run by any user\ . The protocol used is effectively the reverse of the previous protocol\. A75 YR 76 command (without any arguments) starts the authentication exchange\ .230 Client\-side helper for use with arbitrary external programs that may wish to use Samba\'s NTLMSSP authentication knowledge\&. 231 .sp 232 This helper is a client, and as such may be run by any user\&. The protocol used is effectively the reverse of the previous protocol\&. A 233 \FCYR\F[] 234 command (without any arguments) starts the authentication exchange\&. 77 235 .RE 78 236 .PP 79 237 gss\-spnego 80 238 .RS 4 81 Server\-side helper that implements GSS\-SPNEGO\ . This uses a protocol that is almost the same as82 squid\-2\.5\-ntlmssp, but has some subtle differences that are undocumented outside the source at this stage\.239 Server\-side helper that implements GSS\-SPNEGO\&. This uses a protocol that is almost the same as 240 \FCsquid\-2\&.5\-ntlmssp\F[], but has some subtle differences that are undocumented outside the source at this stage\&. 83 241 .sp 84 242 Requires access to the directory 85 \ fIwinbindd_privileged\fR243 \FCwinbindd_privileged\F[] 86 244 in 87 \ fI$LOCKDIR\fR\.245 \FC$LOCKDIR\F[]\&. 88 246 .RE 89 247 .PP 90 248 gss\-spnego\-client 91 249 .RS 4 92 Client\-side helper that implements GSS\-SPNEGO\ . This also uses a protocol similar to the above helpers, but is currently undocumented\.250 Client\-side helper that implements GSS\-SPNEGO\&. This also uses a protocol similar to the above helpers, but is currently undocumented\&. 93 251 .RE 94 252 .PP 95 253 ntlm\-server\-1 96 254 .RS 4 97 Server\-side helper protocol, intended for use by a RADIUS server or the \'winbind\' plugin for pppd, for the provision of MSCHAP and MSCHAPv2 authentication\ .255 Server\-side helper protocol, intended for use by a RADIUS server or the \'winbind\' plugin for pppd, for the provision of MSCHAP and MSCHAPv2 authentication\&. 98 256 .sp 99 257 This protocol consists of lines in the form: 100 Parameter: value 258 \FCParameter: value\F[] 101 259 and 102 Parameter:: Base64\-encode value\. The presence of a single period103 \ .104 indicates that one side has finished supplying data to the other\ . (Which in turn could cause the helper to authenticate the user)\.260 \FCParameter:: Base64\-encode value\F[]\&. The presence of a single period 261 \FC\&.\F[] 262 indicates that one side has finished supplying data to the other\&. (Which in turn could cause the helper to authenticate the user)\&. 105 263 .sp 106 264 Curently implemented parameters from the external program to the helper are: … … 109 267 .RS 4 110 268 The username, expected to be in Samba\'s 111 \ fIunix charset\fR\.112 .PP \fBExample\ 1.\\fR Username: bob113 .PP \fBExample\ 2.\\fR Username:: Ym9i269 \m[blue]\fBunix charset\fR\m[]\&. 270 .PP \fBExample\ \&1.\ \&\fR Username: bob 271 .PP \fBExample\ \&2.\ \&\fR Username:: Ym9i 114 272 .RE 115 273 .PP … … 117 275 .RS 4 118 276 The user\'s domain, expected to be in Samba\'s 119 \ fIunix charset\fR\.120 .PP \fBExample\ 3.\\fR Domain: WORKGROUP121 .PP \fBExample\ 4.\\fR Domain:: V09SS0dST1VQ277 \m[blue]\fBunix charset\fR\m[]\&. 278 .PP \fBExample\ \&3.\ \&\fR Domain: WORKGROUP 279 .PP \fBExample\ \&4.\ \&\fR Domain:: V09SS0dST1VQ 122 280 .RE 123 281 .PP … … 125 283 .RS 4 126 284 The fully qualified username, expected to be in Samba\'s 127 \ fIunix charset\fR285 \m[blue]\fBunix charset\fR\m[] 128 286 and qualified with the 129 \ fIwinbind separator\fR\.130 .PP \fBExample\ 5.\\fR Full\-Username: WORKGROUP\ebob131 .PP \fBExample\ 6.\\fR Full\-Username:: V09SS0dST1VQYm9i287 \m[blue]\fBwinbind separator\fR\m[]\&. 288 .PP \fBExample\ \&5.\ \&\fR Full\-Username: WORKGROUP\ebob 289 .PP \fBExample\ \&6.\ \&\fR Full\-Username:: V09SS0dST1VQYm9i 132 290 .RE 133 291 .PP … … 135 293 .RS 4 136 294 The 8 byte 137 LANMAN Challenge 138 value, generated randomly by the server, or (in cases such as MSCHAPv2) generated in some way by both the server and the client\ .139 .PP \fBExample\ 7.\\fR LANMAN\-Challege: 0102030405060708295 \FCLANMAN Challenge\F[] 296 value, generated randomly by the server, or (in cases such as MSCHAPv2) generated in some way by both the server and the client\&. 297 .PP \fBExample\ \&7.\ \&\fR LANMAN\-Challege: 0102030405060708 140 298 .RE 141 299 .PP … … 143 301 .RS 4 144 302 The 24 byte 145 LANMAN Response 303 \FCLANMAN Response\F[] 146 304 value, calculated from the user\'s password and the supplied 147 LANMAN Challenge\. Typically, this is provided over the network by a client wishing to authenticate\.148 .PP \fBExample\ 8.\\fR LANMAN\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718305 \FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&. 306 .PP \fBExample\ \&8.\ \&\fR LANMAN\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718 149 307 .RE 150 308 .PP … … 152 310 .RS 4 153 311 The >= 24 byte 154 NT Response 312 \FCNT Response\F[] 155 313 calculated from the user\'s password and the supplied 156 LANMAN Challenge\. Typically, this is provided over the network by a client wishing to authenticate\.157 .PP \fBExample\ 9.\\fR NT\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718314 \FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&. 315 .PP \fBExample\ \&9.\ \&\fR NT\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718 158 316 .RE 159 317 .PP 160 318 Password 161 319 .RS 4 162 The user\'s password\ . This would be provided by a network client, if the helper is being used in a legacy situation that exposes plaintext passwords in this way\.163 .PP \fBExample\ 10.\\fR Password: samba2164 .PP \fBExample\ 11.\\fR Password:: c2FtYmEy320 The user\'s password\&. This would be provided by a network client, if the helper is being used in a legacy situation that exposes plaintext passwords in this way\&. 321 .PP \fBExample\ \&10.\ \&\fR Password: samba2 322 .PP \fBExample\ \&11.\ \&\fR Password:: c2FtYmEy 165 323 .RE 166 324 .PP 167 325 Request\-User\-Session\-Key 168 326 .RS 4 169 Apon sucessful authenticaiton, return the user session key associated with the login\ .170 .PP \fBExample\ 12.\\fR Request\-User\-Session\-Key: Yes327 Apon sucessful authenticaiton, return the user session key associated with the login\&. 328 .PP \fBExample\ \&12.\ \&\fR Request\-User\-Session\-Key: Yes 171 329 .RE 172 330 .PP 173 331 Request\-LanMan\-Session\-Key 174 332 .RS 4 175 Apon sucessful authenticaiton, return the LANMAN session key associated with the login\. 176 .PP \fBExample\ 13.\ \fR Request\-LanMan\-Session\-Key: Yes 177 .RE 178 .sp 333 Apon sucessful authenticaiton, return the LANMAN session key associated with the login\&. 334 .PP \fBExample\ \&13.\ \&\fR Request\-LanMan\-Session\-Key: Yes 335 .RE 336 .if n \{\ 337 .sp 338 .\} 339 .RS 4 340 .BM yellow 179 341 .it 1 an-trap 180 342 .nr an-no-space-flag 1 181 343 .nr an-break-flag 1 182 344 .br 183 Warning 345 .ps +1 346 \fBWarning\fR 347 .ps -1 348 .br 184 349 Implementors should take care to base64 encode 185 350 any data (such as usernames/passwords) that may contain malicous user data, such as 186 a newline\. They may also need to decode strings from 187 the helper, which likewise may have been base64 encoded\. 351 a newline\&. They may also need to decode strings from 352 the helper, which likewise may have been base64 encoded\&..sp .5v 353 .EM yellow 354 .RE 188 355 .RE 189 356 .RE … … 223 390 User\'s plaintext password 224 391 .sp 225 If not specified on the command line, this is prompted for when required\ .226 .sp 227 For the NTLMSSP based server roles, this parameter specifies the expected password, allowing testing without winbindd operational\ .392 If not specified on the command line, this is prompted for when required\&. 393 .sp 394 For the NTLMSSP based server roles, this parameter specifies the expected password, allowing testing without winbindd operational\&. 228 395 .RE 229 396 .PP … … 240 407 \-\-diagnostics 241 408 .RS 4 242 Perform Diagnostics on the authentication chain\ . Uses the password from243 \ -\-password244 or prompts for one\ .409 Perform Diagnostics on the authentication chain\&. Uses the password from 410 \FC\-\-password\F[] 411 or prompts for one\&. 245 412 .RE 246 413 .PP 247 414 \-\-require\-membership\-of={SID|Name} 248 415 .RS 4 249 Require that a user be a member of specified group (either name or SID) for authentication to succeed\ .416 Require that a user be a member of specified group (either name or SID) for authentication to succeed\&. 250 417 .RE 251 418 .PP … … 253 420 .RS 4 254 421 \fIlevel\fR 255 is an integer from 0 to 10\ . The default value if this parameter is not specified is 0\.256 .sp 257 The higher this value, the more detail will be logged to the log files about the activities of the server\ . At level 0, only critical errors and serious warnings will be logged\. Level 1 is a reasonable level for day\-to\-day running \- it generates a small amount of information about operations carried out\.258 .sp 259 Levels above 1 will generate considerable amounts of log data, and should only be used when investigating a problem\ . Levels above 3 are designed for use only by developers and generate HUGE amounts of log data, most of which is extremely cryptic\.422 is an integer from 0 to 10\&. The default value if this parameter is not specified is 0\&. 423 .sp 424 The higher this value, the more detail will be logged to the log files about the activities of the server\&. At level 0, only critical errors and serious warnings will be logged\&. Level 1 is a reasonable level for day\-to\-day running \- it generates a small amount of information about operations carried out\&. 425 .sp 426 Levels above 1 will generate considerable amounts of log data, and should only be used when investigating a problem\&. Levels above 3 are designed for use only by developers and generate HUGE amounts of log data, most of which is extremely cryptic\&. 260 427 .sp 261 428 Note that specifying this parameter here will override the 262 \ fIlog level\fR429 \m[blue]\fBlog level\fR\m[] 263 430 parameter in the 264 \ fIsmb\.conf\fR265 file\ .431 \FCsmb\&.conf\F[] 432 file\&. 266 433 .RE 267 434 .PP 268 435 \-V 269 436 .RS 4 270 Prints the program version number\ .437 Prints the program version number\&. 271 438 .RE 272 439 .PP 273 440 \-s <configuration file> 274 441 .RS 4 275 The file specified contains the configuration details required by the server\ . The information in this file includes server\-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide\. See276 \ fIsmb\.conf\fR277 for more information\ . The default configuration file name is determined at compile time\.442 The file specified contains the configuration details required by the server\&. The information in this file includes server\-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide\&. See 443 \FCsmb\&.conf\F[] 444 for more information\&. The default configuration file name is determined at compile time\&. 278 445 .RE 279 446 .PP 280 447 \-l|\-\-log\-basename=logdirectory 281 448 .RS 4 282 Base directory name for log/debug files\ . The extension283 \fB"\ .progname"\fR284 will be appended (e\ .g\. log\.smbclient, log\.smbd, etc\.\.\.)\. The log file is never removed by the client\.449 Base directory name for log/debug files\&. The extension 450 \fB"\&.progname"\fR 451 will be appended (e\&.g\&. log\&.smbclient, log\&.smbd, etc\&.\&.\&.)\&. The log file is never removed by the client\&. 285 452 .RE 286 453 .PP 287 454 \-h|\-\-help 288 455 .RS 4 289 Print a summary of command line options\ .456 Print a summary of command line options\&. 290 457 .RE 291 458 .SH "EXAMPLE SETUP" 292 459 .PP 293 To setup ntlm_auth for use by squid 2\.5, with both basic and NTLMSSP authentication, the following should be placed in the 294 \fIsquid\.conf\fR 295 file\. 296 .sp 297 .RS 4 460 To setup ntlm_auth for use by squid 2\&.5, with both basic and NTLMSSP authentication, the following should be placed in the 461 \FCsquid\&.conf\F[] 462 file\&. 463 .sp 464 .if n \{\ 465 .RS 4 466 .\} 467 .fam C 468 .ps -1 298 469 .nf 299 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-ntlmssp 300 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-basic 470 .if t \{\ 471 .sp -1 472 .\} 473 .BB lightgray adjust-for-leading-newline 474 .sp -1 475 476 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp 477 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic 301 478 auth_param basic children 5 302 479 auth_param basic realm Squid proxy\-caching web server 303 480 auth_param basic credentialsttl 2 hours 481 .EB lightgray adjust-for-leading-newline 482 .if t \{\ 483 .sp 1 484 .\} 304 485 .fi 305 .RE 306 .sp 486 .fam 487 .ps +1 488 .if n \{\ 489 .RE 490 .\} 491 .if n \{\ 492 .sp 493 .\} 494 .RS 4 495 .BM yellow 307 496 .it 1 an-trap 308 497 .nr an-no-space-flag 1 309 498 .nr an-break-flag 1 310 499 .br 311 Note 500 .ps +1 501 \fBNote\fR 502 .ps -1 503 .br 312 504 .PP 313 505 This example assumes that ntlm_auth has been installed into your path, and that the group permissions on 314 \fIwinbindd_privileged\fR 315 are as described above\. 316 .PP 317 To setup ntlm_auth for use by squid 2\.5 with group limitation in addition to the above example, the following should be added to the 318 \fIsquid\.conf\fR 319 file\. 320 .sp 321 .RS 4 506 \FCwinbindd_privileged\F[] 507 are as described above\&. 508 .sp .5v 509 .EM yellow 510 .RE 511 .PP 512 To setup ntlm_auth for use by squid 2\&.5 with group limitation in addition to the above example, the following should be added to the 513 \FCsquid\&.conf\F[] 514 file\&. 515 .sp 516 .if n \{\ 517 .RS 4 518 .\} 519 .fam C 520 .ps -1 322 521 .nf 323 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-ntlmssp \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\' 324 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\.5\-basic \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\' 522 .if t \{\ 523 .sp -1 524 .\} 525 .BB lightgray adjust-for-leading-newline 526 .sp -1 527 528 auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\' 529 auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\' 530 .EB lightgray adjust-for-leading-newline 531 .if t \{\ 532 .sp 1 533 .\} 325 534 .fi 326 .RE 535 .fam 536 .ps +1 537 .if n \{\ 538 .RE 539 .\} 327 540 .SH "TROUBLESHOOTING" 328 541 .PP 329 If you\'re experiencing problems with authenticating Internet Explorer running under MS Windows 9X or Millenium Edition against ntlm_auth\'s NTLMSSP authentication helper (\-\-helper\-protocol=squid\-2\ .5\-ntlmssp), then please read330 the Microsoft Knowledge Base article #239869 and follow instructions described there\ .542 If you\'re experiencing problems with authenticating Internet Explorer running under MS Windows 9X or Millenium Edition against ntlm_auth\'s NTLMSSP authentication helper (\-\-helper\-protocol=squid\-2\&.5\-ntlmssp), then please read 543 the Microsoft Knowledge Base article #239869 and follow instructions described there\&. 331 544 .SH "VERSION" 332 545 .PP 333 This man page is correct for version 3\ .0 of the Samba suite\.546 This man page is correct for version 3\&.0 of the Samba suite\&. 334 547 .SH "AUTHOR" 335 548 .PP 336 The original Samba software and related utilities were created by Andrew Tridgell\ . Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\.337 .PP 338 The ntlm_auth manpage was written by Jelmer Vernooij and Andrew Bartlett\ .549 The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&. 550 .PP 551 The ntlm_auth manpage was written by Jelmer Vernooij and Andrew Bartlett\&.
Note:
See TracChangeset
for help on using the changeset viewer.