Ignore:
Timestamp:
Jul 2, 2011, 3:35:33 PM (14 years ago)
Author:
Herwig Bauernfeind
Message:

Samba 3.5: Update trunk to 3.5.8

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/server/docs/manpages/ntlm_auth.1

    r480 r596  
     1'\" t
    12.\"     Title: ntlm_auth
    23.\"    Author: [see the "AUTHOR" section]
    3 .\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
    4 .\"      Date: 06/18/2010
     4.\" Generator: DocBook XSL Stylesheets v1.75.2 <http://docbook.sf.net/>
     5.\"      Date: 03/06/2011
    56.\"    Manual: User Commands
    67.\"    Source: Samba 3.5
    78.\"  Language: English
    89.\"
    9 .TH "NTLM_AUTH" "1" "06/18/2010" "Samba 3\&.5" "User Commands"
    10 .\" -----------------------------------------------------------------
    11 .\" * (re)Define some macros
    12 .\" -----------------------------------------------------------------
    13 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    14 .\" toupper - uppercase a string (locale-aware)
    15 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    16 .de toupper
    17 .tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
    18 \\$*
    19 .tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
    20 ..
    21 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    22 .\" SH-xref - format a cross-reference to an SH section
    23 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    24 .de SH-xref
    25 .ie n \{\
    26 .\}
    27 .toupper \\$*
    28 .el \{\
    29 \\$*
    30 .\}
    31 ..
    32 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    33 .\" SH - level-one heading that works better for non-TTY output
    34 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    35 .de1 SH
    36 .\" put an extra blank line of space above the head in non-TTY output
    37 .if t \{\
    38 .sp 1
    39 .\}
    40 .sp \\n[PD]u
    41 .nr an-level 1
    42 .set-an-margin
    43 .nr an-prevailing-indent \\n[IN]
    44 .fi
    45 .in \\n[an-margin]u
    46 .ti 0
    47 .HTML-TAG ".NH \\n[an-level]"
    48 .it 1 an-trap
    49 .nr an-no-space-flag 1
    50 .nr an-break-flag 1
    51 \." make the size of the head bigger
    52 .ps +3
    53 .ft B
    54 .ne (2v + 1u)
    55 .ie n \{\
    56 .\" if n (TTY output), use uppercase
    57 .toupper \\$*
    58 .\}
    59 .el \{\
    60 .nr an-break-flag 0
    61 .\" if not n (not TTY), use normal case (not uppercase)
    62 \\$1
    63 .in \\n[an-margin]u
    64 .ti 0
    65 .\" if not n (not TTY), put a border/line under subheading
    66 .sp -.6
    67 \l'\n(.lu'
    68 .\}
    69 ..
    70 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    71 .\" SS - level-two heading that works better for non-TTY output
    72 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    73 .de1 SS
    74 .sp \\n[PD]u
    75 .nr an-level 1
    76 .set-an-margin
    77 .nr an-prevailing-indent \\n[IN]
    78 .fi
    79 .in \\n[IN]u
    80 .ti \\n[SN]u
    81 .it 1 an-trap
    82 .nr an-no-space-flag 1
    83 .nr an-break-flag 1
    84 .ps \\n[PS-SS]u
    85 \." make the size of the head bigger
    86 .ps +2
    87 .ft B
    88 .ne (2v + 1u)
    89 .if \\n[.$] \&\\$*
    90 ..
    91 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    92 .\" BB/BE - put background/screen (filled box) around block of text
    93 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    94 .de BB
    95 .if t \{\
    96 .sp -.5
    97 .br
    98 .in +2n
    99 .ll -2n
    100 .gcolor red
    101 .di BX
    102 .\}
    103 ..
    104 .de EB
    105 .if t \{\
    106 .if "\\$2"adjust-for-leading-newline" \{\
    107 .sp -1
    108 .\}
    109 .br
    110 .di
    111 .in
    112 .ll
    113 .gcolor
    114 .nr BW \\n(.lu-\\n(.i
    115 .nr BH \\n(dn+.5v
    116 .ne \\n(BHu+.5v
    117 .ie "\\$2"adjust-for-leading-newline" \{\
    118 \M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
    119 .\}
    120 .el \{\
    121 \M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
    122 .\}
    123 .in 0
    124 .sp -.5v
    125 .nf
    126 .BX
    127 .in
    128 .sp .5v
    129 .fi
    130 .\}
    131 ..
    132 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    133 .\" BM/EM - put colored marker in margin next to block of text
    134 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    135 .de BM
    136 .if t \{\
    137 .br
    138 .ll -2n
    139 .gcolor red
    140 .di BX
    141 .\}
    142 ..
    143 .de EM
    144 .if t \{\
    145 .br
    146 .di
    147 .ll
    148 .gcolor
    149 .nr BH \\n(dn
    150 .ne \\n(BHu
    151 \M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
    152 .in 0
    153 .nf
    154 .BX
    155 .in
    156 .fi
    157 .\}
    158 ..
     10.TH "NTLM_AUTH" "1" "03/06/2011" "Samba 3\&.5" "User Commands"
    15911.\" -----------------------------------------------------------------
    16012.\" * set default formatting
     
    16719.\" * MAIN CONTENT STARTS HERE *
    16820.\" -----------------------------------------------------------------
    169 .SH "Name"
     21.SH "NAME"
    17022ntlm_auth \- tool to allow external access to Winbind\'s NTLM authentication function
    171 .SH "Synopsis"
    172 .fam C
     23.SH "SYNOPSIS"
    17324.HP \w'\ 'u
    174 \FCntlm_auth\F[] [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>]
    175 .fam
     25ntlm_auth [\-d\ debuglevel] [\-l\ logdir] [\-s\ <smb\ config\ file>]
    17626.SH "DESCRIPTION"
    17727.PP
     
    18030suite\&.
    18131.PP
    182 \FCntlm_auth\F[]
     32ntlm_auth
    18333is a helper utility that authenticates users using NT/LM authentication\&. It returns 0 if the users is authenticated successfully and 1 if access was denied\&. ntlm_auth uses winbind to access the user and authentication data for a domain\&. This utility is only intended to be used by other programs (currently
    18434Squid
     
    19242.PP
    19343Some of these commands also require access to the directory
    194 \FCwinbindd_privileged\F[]
     44winbindd_privileged
    19545in
    196 \FC$LOCKDIR\F[]\&. This should be done either by running this command as root or providing group access to the
    197 \FCwinbindd_privileged\F[]
     46$LOCKDIR\&. This should be done either by running this command as root or providing group access to the
     47winbindd_privileged
    19848directory\&. For security reasons, this directory should not be world\-accessable\&.
    19949.SH "OPTIONS"
     
    21868.sp
    21969Requires access to the directory
    220 \FCwinbindd_privileged\F[]
     70winbindd_privileged
    22171in
    222 \FC$LOCKDIR\F[]\&. The protocol used is described here:
     72$LOCKDIR\&. The protocol used is described here:
    22373http://devel\&.squid\-cache\&.org/ntlm/squid_helper_protocol\&.html\&. This protocol has been extended to allow the NTLMSSP Negotiate packet to be included as an argument to the
    224 \FCYR\F[]
     74YR
    22575command\&. (Thus avoiding loss of information in the protocol exchange)\&.
    22676.RE
     
    23181.sp
    23282This helper is a client, and as such may be run by any user\&. The protocol used is effectively the reverse of the previous protocol\&. A
    233 \FCYR\F[]
     83YR
    23484command (without any arguments) starts the authentication exchange\&.
    23585.RE
     
    23888.RS 4
    23989Server\-side helper that implements GSS\-SPNEGO\&. This uses a protocol that is almost the same as
    240 \FCsquid\-2\&.5\-ntlmssp\F[], but has some subtle differences that are undocumented outside the source at this stage\&.
     90squid\-2\&.5\-ntlmssp, but has some subtle differences that are undocumented outside the source at this stage\&.
    24191.sp
    24292Requires access to the directory
    243 \FCwinbindd_privileged\F[]
     93winbindd_privileged
    24494in
    245 \FC$LOCKDIR\F[]\&.
     95$LOCKDIR\&.
    24696.RE
    24797.PP
     
    256106.sp
    257107This protocol consists of lines in the form:
    258 \FCParameter: value\F[]
     108Parameter: value
    259109and
    260 \FCParameter:: Base64\-encode value\F[]\&. The presence of a single period
    261 \FC\&.\F[]
     110Parameter:: Base64\-encode value\&. The presence of a single period
     111\&.
    262112indicates that one side has finished supplying data to the other\&. (Which in turn could cause the helper to authenticate the user)\&.
    263113.sp
     
    293143.RS 4
    294144The 8 byte
    295 \FCLANMAN Challenge\F[]
     145LANMAN Challenge
    296146value, generated randomly by the server, or (in cases such as MSCHAPv2) generated in some way by both the server and the client\&.
    297147.PP \fBExample\ \&7.\ \&\fR LANMAN\-Challege: 0102030405060708
     
    301151.RS 4
    302152The 24 byte
    303 \FCLANMAN Response\F[]
     153LANMAN Response
    304154value, calculated from the user\'s password and the supplied
    305 \FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&.
     155LANMAN Challenge\&. Typically, this is provided over the network by a client wishing to authenticate\&.
    306156.PP \fBExample\ \&8.\ \&\fR LANMAN\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
    307157.RE
     
    310160.RS 4
    311161The >= 24 byte
    312 \FCNT Response\F[]
     162NT Response
    313163calculated from the user\'s password and the supplied
    314 \FCLANMAN Challenge\F[]\&. Typically, this is provided over the network by a client wishing to authenticate\&.
     164LANMAN Challenge\&. Typically, this is provided over the network by a client wishing to authenticate\&.
    315165.PP \fBExample\ \&9.\ \&\fR NT\-Response: 0102030405060708090A0B0C0D0E0F101112131415161718
    316166.RE
     
    338188.\}
    339189.RS 4
    340 .BM yellow
    341190.it 1 an-trap
    342191.nr an-no-space-flag 1
     
    351200                a newline\&.  They may also need to decode strings from
    352201                the helper, which likewise may have been base64 encoded\&..sp .5v
    353 .EM yellow
    354202.RE
    355203.RE
     
    408256.RS 4
    409257Perform Diagnostics on the authentication chain\&. Uses the password from
    410 \FC\-\-password\F[]
     258\-\-password
    411259or prompts for one\&.
    412260.RE
     
    429277\m[blue]\fB\%smb.conf.5.html#\fR\m[]
    430278parameter in the
    431 \FCsmb\&.conf\F[]
     279smb\&.conf
    432280file\&.
    433281.RE
     
    441289.RS 4
    442290The file specified contains the configuration details required by the server\&. The information in this file includes server\-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide\&. See
    443 \FCsmb\&.conf\F[]
     291smb\&.conf
    444292for more information\&. The default configuration file name is determined at compile time\&.
    445293.RE
     
    459307.PP
    460308To setup ntlm_auth for use by squid 2\&.5, with both basic and NTLMSSP authentication, the following should be placed in the
    461 \FCsquid\&.conf\F[]
     309squid\&.conf
    462310file\&.
    463311.sp
     
    465313.RS 4
    466314.\}
    467 .fam C
    468 .ps -1
    469315.nf
    470 .if t \{\
    471 .sp -1
    472 .\}
    473 .BB lightgray adjust-for-leading-newline
    474 .sp -1
    475 
    476316auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp
    477317auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic
     
    479319auth_param basic realm Squid proxy\-caching web server
    480320auth_param basic credentialsttl 2 hours
    481 .EB lightgray adjust-for-leading-newline
    482 .if t \{\
    483 .sp 1
    484 .\}
    485321.fi
    486 .fam
    487 .ps +1
    488 .if n \{\
    489 .RE
    490 .\}
    491 .if n \{\
    492 .sp
    493 .\}
    494 .RS 4
    495 .BM yellow
     322.if n \{\
     323.RE
     324.\}
     325.if n \{\
     326.sp
     327.\}
     328.RS 4
    496329.it 1 an-trap
    497330.nr an-no-space-flag 1
     
    504337.PP
    505338This example assumes that ntlm_auth has been installed into your path, and that the group permissions on
    506 \FCwinbindd_privileged\F[]
     339winbindd_privileged
    507340are as described above\&.
    508341.sp .5v
    509 .EM yellow
    510342.RE
    511343.PP
    512344To setup ntlm_auth for use by squid 2\&.5 with group limitation in addition to the above example, the following should be added to the
    513 \FCsquid\&.conf\F[]
     345squid\&.conf
    514346file\&.
    515347.sp
     
    517349.RS 4
    518350.\}
    519 .fam C
    520 .ps -1
    521351.nf
    522 .if t \{\
    523 .sp -1
    524 .\}
    525 .BB lightgray adjust-for-leading-newline
    526 .sp -1
    527 
    528352auth_param ntlm program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-ntlmssp \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
    529353auth_param basic program ntlm_auth \-\-helper\-protocol=squid\-2\&.5\-basic \-\-require\-membership\-of=\'WORKGROUP\eDomain Users\'
    530 .EB lightgray adjust-for-leading-newline
    531 .if t \{\
    532 .sp 1
    533 .\}
    534354.fi
    535 .fam
    536 .ps +1
    537355.if n \{\
    538356.RE
Note: See TracChangeset for help on using the changeset viewer.