diff options
author | Gerald Carter <jerry@samba.org> | 2007-03-21 20:22:12 +0000 |
---|---|---|
committer | Gerald W. Carter <jerry@samba.org> | 2008-04-23 08:47:29 -0500 |
commit | 1512393605152275a8d3610da9171678851e72c3 (patch) | |
tree | b7d7a144c74cc8666b617ce1ed5d4da88b50f62e /docs/smbdotconf | |
parent | c52661aa20ea39ec3c21d60d7b00a6b7f324cab6 (diff) | |
download | samba-1512393605152275a8d3610da9171678851e72c3.tar.gz samba-1512393605152275a8d3610da9171678851e72c3.tar.bz2 samba-1512393605152275a8d3610da9171678851e72c3.zip |
more idmap doc updates
(This used to be commit 7462399b5cb185ab442c69950ef337c497e3e6f5)
Diffstat (limited to 'docs/smbdotconf')
-rw-r--r-- | docs/smbdotconf/winbind/idmapbackend.xml | 4 | ||||
-rw-r--r-- | docs/smbdotconf/winbind/idmapconfig.xml | 53 | ||||
-rw-r--r-- | docs/smbdotconf/winbind/idmapdomains.xml | 6 |
3 files changed, 47 insertions, 16 deletions
diff --git a/docs/smbdotconf/winbind/idmapbackend.xml b/docs/smbdotconf/winbind/idmapbackend.xml index c9049c6af0..20e1115c5f 100644 --- a/docs/smbdotconf/winbind/idmapbackend.xml +++ b/docs/smbdotconf/winbind/idmapbackend.xml @@ -24,7 +24,5 @@ </para> </description> -<value type="default"></value> -<value type="example">ldap:ldap://ldapslave.example.com/</value> -<value type="example">ad</value> +<value type="default">tdb</value> </samba:parameter> diff --git a/docs/smbdotconf/winbind/idmapconfig.xml b/docs/smbdotconf/winbind/idmapconfig.xml index 7e96445962..63b0a907a8 100644 --- a/docs/smbdotconf/winbind/idmapconfig.xml +++ b/docs/smbdotconf/winbind/idmapconfig.xml @@ -8,24 +8,57 @@ The idmap config prefix provides a means of managing each domain defined by the <smbconfoption name="idmap domains"/> option using Samba's parameteric option support. The idmap config prefix should be - followed by the name of the domain, a colon, and either the option - name "backend" or a setting specific to the chosen - backend.</para> + followed by the name of the domain, a colon, and a setting specific to + the chosen backend. There are three options available for all domains: + </para> + <variablelist> + <varlistentry> + <term>backend = backend_name</term> + <listitem><para> + Specifies the name of the idmap plugin to use as the + SID/uid/gid backend for this domain. + </para></listitem> + </varlistentry> + + <varlistentry> + <term>default = [yes|no]</term> + <listitem><para> + The default domain/backend will be used for searching for + users and groups not belonging to one of the explicitly + listed domains (matched by comparing the account SID and the + domain SID). + </para></listitem> + </varlistentry> + + <varlistentry> + <term>readonly = [yes|no]</term> + <listitem><para> + Mark the domain as readonly which means that no attempts to + allocate a uid or gid (by the <smbconfoption name="idmap alloc + backend"/>) for any user or group in that domain + will be attempted. + </para></listitem> + </varlistentry> + </variablelist> <para> The following example illustrates how to configure the <citerefentry> <refentrytitle>idmap_ad</refentrytitle><manvolnum>8</manvolnum></citerefentry> for the CORP domain and the <citerefentry><refentrytitle>idmap_tdb</refentrytitle> - <manvolnum>8</manvolnum></citerefentry> backend for all other domains. + <manvolnum>8</manvolnum></citerefentry> backend for all other domains. The + TRUSTEDDOMAINS string is simply a key used to reference the "idmap + config" settings and does not represent the actual name of a domain. </para> <programlisting> - idmap domains = CORP default - idmap config CORP:backend = ad - idmap config CORP:read_only = yes - idmap config default:backend = tdb - idmap config default:default = yes - idmap config default:range = 1000 - 9999 + idmap domains = CORP TRUSTEDDOMAINS + + idmap config CORP:backend = ad + idmap config CORP:readonly = yes + + idmap config TRUSTEDDOMAINS:backend = tdb + idmap config TRUSTEDDOMAINS:default = yes + idmap config TRUSTEDDOMAINS:range = 1000 - 9999 </programlisting> </description> diff --git a/docs/smbdotconf/winbind/idmapdomains.xml b/docs/smbdotconf/winbind/idmapdomains.xml index 515a91ba79..131b9e8167 100644 --- a/docs/smbdotconf/winbind/idmapdomains.xml +++ b/docs/smbdotconf/winbind/idmapdomains.xml @@ -12,9 +12,9 @@ </para> <para> - Values constist of the short domain name for Winbind's primary or collection - of trusted domains. The keyword "default" is used to - represent all domains not explicitly listed. + Values consist of the short domain name for Winbind's primary or collection + of trusted domains. You may also use an arbitrary string to represent a catchall + domain backend for any domain not explicitly listed. </para> <para> |