source: vendor/current/docs/manpages/winbindd.8@ 427

Last change on this file since 427 was 427, checked in by Silvan Scherrer, 16 years ago

Samba 3.5.x: update to 3.5.2

File size: 20.7 KB
RevLine 
[427]1.\" Title: winbindd
2.\" Author: [see the "AUTHOR" section]
3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
4.\" Date: 03/30/2010
5.\" Manual: System Administration tools
6.\" Source: Samba 3.5
7.\" Language: English
8.\"
9.TH "WINBINDD" "8" "03/30/2010" "Samba 3\&.5" "System Administration tools"
10.\" -----------------------------------------------------------------
11.\" * (re)Define some macros
12.\" -----------------------------------------------------------------
13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
14.\" toupper - uppercase a string (locale-aware)
15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
16.de toupper
17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
18\\$*
19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
20..
21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
22.\" SH-xref - format a cross-reference to an SH section
23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
24.de SH-xref
25.ie n \{\
26.\}
27.toupper \\$*
28.el \{\
29\\$*
30.\}
31..
32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
33.\" SH - level-one heading that works better for non-TTY output
34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
35.de1 SH
36.\" put an extra blank line of space above the head in non-TTY output
37.if t \{\
38.sp 1
39.\}
40.sp \\n[PD]u
41.nr an-level 1
42.set-an-margin
43.nr an-prevailing-indent \\n[IN]
44.fi
45.in \\n[an-margin]u
46.ti 0
47.HTML-TAG ".NH \\n[an-level]"
48.it 1 an-trap
49.nr an-no-space-flag 1
50.nr an-break-flag 1
51\." make the size of the head bigger
52.ps +3
53.ft B
54.ne (2v + 1u)
55.ie n \{\
56.\" if n (TTY output), use uppercase
57.toupper \\$*
58.\}
59.el \{\
60.nr an-break-flag 0
61.\" if not n (not TTY), use normal case (not uppercase)
62\\$1
63.in \\n[an-margin]u
64.ti 0
65.\" if not n (not TTY), put a border/line under subheading
66.sp -.6
67\l'\n(.lu'
68.\}
69..
70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
71.\" SS - level-two heading that works better for non-TTY output
72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
73.de1 SS
74.sp \\n[PD]u
75.nr an-level 1
76.set-an-margin
77.nr an-prevailing-indent \\n[IN]
78.fi
79.in \\n[IN]u
80.ti \\n[SN]u
81.it 1 an-trap
82.nr an-no-space-flag 1
83.nr an-break-flag 1
84.ps \\n[PS-SS]u
85\." make the size of the head bigger
86.ps +2
87.ft B
88.ne (2v + 1u)
89.if \\n[.$] \&\\$*
90..
91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
92.\" BB/BE - put background/screen (filled box) around block of text
93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
94.de BB
95.if t \{\
96.sp -.5
97.br
98.in +2n
99.ll -2n
100.gcolor red
101.di BX
102.\}
103..
104.de EB
105.if t \{\
106.if "\\$2"adjust-for-leading-newline" \{\
107.sp -1
108.\}
109.br
110.di
111.in
112.ll
113.gcolor
114.nr BW \\n(.lu-\\n(.i
115.nr BH \\n(dn+.5v
116.ne \\n(BHu+.5v
117.ie "\\$2"adjust-for-leading-newline" \{\
118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
119.\}
120.el \{\
121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
122.\}
123.in 0
124.sp -.5v
125.nf
126.BX
127.in
128.sp .5v
129.fi
130.\}
131..
132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
133.\" BM/EM - put colored marker in margin next to block of text
134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
135.de BM
136.if t \{\
137.br
138.ll -2n
139.gcolor red
140.di BX
141.\}
142..
143.de EM
144.if t \{\
145.br
146.di
147.ll
148.gcolor
149.nr BH \\n(dn
150.ne \\n(BHu
151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
152.in 0
153.nf
154.BX
155.in
156.fi
157.\}
158..
159.\" -----------------------------------------------------------------
160.\" * set default formatting
161.\" -----------------------------------------------------------------
162.\" disable hyphenation
163.nh
164.\" disable justification (adjust text to left margin only)
165.ad l
166.\" -----------------------------------------------------------------
167.\" * MAIN CONTENT STARTS HERE *
168.\" -----------------------------------------------------------------
169.SH "Name"
170winbindd \- Name Service Switch daemon for resolving names from NT servers
171.SH "Synopsis"
172.fam C
173.HP \w'\ 'u
174\FCwinbindd\F[] [\-D] [\-F] [\-S] [\-i] [\-Y] [\-d\ <debug\ level>] [\-s\ <smb\ config\ file>] [\-n]
175.fam
176.SH "DESCRIPTION"
177.PP
178This program is part of the
179\fBsamba\fR(7)
180suite\&.
181.PP
182\FCwinbindd\F[]
183is a daemon that provides a number of services to the Name Service Switch capability found in most modern C libraries, to arbitrary applications via PAM and
184\FCntlm_auth\F[]
185and to Samba itself\&.
186.PP
187Even if winbind is not used for nsswitch, it still provides a service to
188\FCsmbd\F[],
189\FCntlm_auth\F[]
190and the
191\FCpam_winbind\&.so\F[]
192PAM module, by managing connections to domain controllers\&. In this configuraiton the
193\m[blue]\fBidmap uid\fR\m[]
194and
195\m[blue]\fBidmap gid\fR\m[]
196parameters are not required\&. (This is known as `netlogon proxy only mode\'\&.)
197.PP
198The Name Service Switch allows user and system information to be obtained from different databases services such as NIS or DNS\&. The exact behaviour can be configured through the
199\FC/etc/nsswitch\&.conf\F[]
200file\&. Users and groups are allocated as they are resolved to a range of user and group ids specified by the administrator of the Samba system\&.
201.PP
202The service provided by
203\FCwinbindd\F[]
204is called `winbind\' and can be used to resolve user and group information from a Windows NT server\&. The service can also provide authentication services via an associated PAM module\&.
205.PP
206The
207\FCpam_winbind\F[]
208module supports the
209\fIauth\fR,
210\fIaccount\fR
211and
212\fIpassword\fR
213module\-types\&. It should be noted that the
214\fIaccount\fR
215module simply performs a getpwnam() to verify that the system can obtain a uid for the user, as the domain controller has already performed access control\&. If the
216\FClibnss_winbind\F[]
217library has been correctly installed, or an alternate source of names configured, this should always succeed\&.
218.PP
219The following nsswitch databases are implemented by the winbindd service:
220.PP
221\-D
222.RS 4
223If specified, this parameter causes the server to operate as a daemon\&. That is, it detaches itself and runs in the background on the appropriate port\&. This switch is assumed if
224\FCwinbindd\F[]
225is executed on the command line of a shell\&.
226.RE
227.PP
228hosts
229.RS 4
230This feature is only available on IRIX\&. User information traditionally stored in the
231\FChosts(5)\F[]
232file and used by
233\FCgethostbyname(3)\F[]
234functions\&. Names are resolved through the WINS server or by broadcast\&.
235.RE
236.PP
237passwd
238.RS 4
239User information traditionally stored in the
240\FCpasswd(5)\F[]
241file and used by
242\FCgetpwent(3)\F[]
243functions\&.
244.RE
245.PP
246group
247.RS 4
248Group information traditionally stored in the
249\FCgroup(5)\F[]
250file and used by
251\FCgetgrent(3)\F[]
252functions\&.
253.RE
254.PP
255For example, the following simple configuration in the
256\FC/etc/nsswitch\&.conf\F[]
257file can be used to initially resolve user and group information from
258\FC/etc/passwd \F[]
259and
260\FC/etc/group\F[]
261and then from the Windows NT server\&.
262.sp
263.if n \{\
264.RS 4
265.\}
266.fam C
267.ps -1
268.nf
269.if t \{\
270.sp -1
271.\}
272.BB lightgray adjust-for-leading-newline
273.sp -1
274
275passwd: files winbind
276group: files winbind
277## only available on IRIX: use winbind to resolve hosts:
278# hosts: files dns winbind
279## All other NSS enabled systems should use libnss_wins\&.so like this:
280hosts: files dns wins
281
282.EB lightgray adjust-for-leading-newline
283.if t \{\
284.sp 1
285.\}
286.fi
287.fam
288.ps +1
289.if n \{\
290.RE
291.\}
292.PP
293The following simple configuration in the
294\FC/etc/nsswitch\&.conf\F[]
295file can be used to initially resolve hostnames from