From 8daa83a594a2e98f39d764422bfbdbc62c9efd44 Mon Sep 17 00:00:00 2001 From: Daniel Baumann Date: Fri, 19 Apr 2024 19:20:00 +0200 Subject: Adding upstream version 2:4.20.0+dfsg. Signed-off-by: Daniel Baumann --- docs-xml/manpages/idmap_nss.8.xml | 98 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 98 insertions(+) create mode 100644 docs-xml/manpages/idmap_nss.8.xml (limited to 'docs-xml/manpages/idmap_nss.8.xml') diff --git a/docs-xml/manpages/idmap_nss.8.xml b/docs-xml/manpages/idmap_nss.8.xml new file mode 100644 index 0000000..a9c6ece --- /dev/null +++ b/docs-xml/manpages/idmap_nss.8.xml @@ -0,0 +1,98 @@ + + + + + + idmap_nss + 8 + Samba + System Administration tools + &doc.version; + + + + + idmap_nss + Samba's idmap_nss Backend for Winbind + + + + DESCRIPTION + + The idmap_nss plugin provides a means to map Unix users and groups + to Windows accounts. This provides a simple means of ensuring that the SID + for a Unix user named jsmith is reported as the one assigned to + DOMAIN\jsmith which is necessary for reporting ACLs on files and printers + stored on a Samba member server. + + + + + IDMAP OPTIONS + + + + range = low - high + + Defines the available matching UID and GID range for which the + backend is authoritative. Note that the range acts as a filter. + Returned UIDs or GIDs by NSS modules that fall outside the range + are ignored and the corresponding maps discarded. It is intended + as a way to avoid accidental UID/GID overlaps between local and + remotely defined IDs. + + + + + use_upn = <yes | no> + + + Some NSS modules can return and handle UPNs and/or down-level + logon names (e.g., DOMAIN\user or user@REALM). + + + If this parameter is enabled the returned names from NSS will be + parsed and the resulting namespace will be used as the authoritative + namespace instead of the IDMAP domain name. Also, down-level logon + names will be sent to NSS instead of the plain username to give NSS + modules a hint about the user's correct domain. + + Default: no + + + + + + + + + EXAMPLES + + + This example shows how to use idmap_nss to obtain the local account ID's + for its own domain (SAMBA) from NSS, whilst allocating new mappings for + the default domain (*) and any trusted domains. + + + + [global] + idmap config * : backend = tdb + idmap config * : range = 1000000-1999999 + + idmap config SAMBA : backend = nss + idmap config SAMBA : range = 1000-999999 + + + + + AUTHOR + + + The original Samba software and related utilities + were created by Andrew Tridgell. Samba is now developed + by the Samba Team as an Open Source project similar + to the way the Linux kernel is developed. + + + + -- cgit v1.2.3