~ubuntu-branches/ubuntu/maverick/samba/maverick-security

« back to all changes in this revision

Viewing changes to docs/htmldocs/manpages/idmap_hash.8.html

  • Committer: Bazaar Package Importer
  • Author(s): Chuck Short
  • Date: 2010-01-29 06:16:15 UTC
  • mfrom: (0.27.9 upstream) (0.34.4 squeeze)
  • Revision ID: james.westby@ubuntu.com-20100129061615-37hs6xqpsdhjq3ld
Tags: 2:3.4.5~dfsg-1ubuntu1
* Merge from debian testing.  Remaining changes:
  + debian/patches/VERSION.patch:
    - set SAMBA_VERSION_SUFFIX to Ubuntu.
  + debian/smb.conf:
    - Add "(Samba, Ubuntu)" to server string.
    - Comment out the default [homes] share, and add a comment about "valid users = %s"
      to show users how to restrict access to \\server\username to only username.
    - Set 'usershare allow guests', so that usershare admins are allowed to create
      public shares in additon to authenticated ones.
    - add map to guest = Bad user, maps bad username to gues access.
  + debian/samba-common.conf:
    - Do not change priority to high if dhclient3 is installed.
    - Use priority medium instead of high for the workgroup question.
  + debian/mksambapasswd.awk:
    - Do not add user with UID less than 1000 to smbpasswd.
  + debian/control: 
    - Make libswbclient0 replace/conflict with hardy's likewise-open.
    - Don't build against ctdb, since its not in main yet.
  + debian/rules:
    - Enable "native" PIE hardening.
    - Add BIND_NOW to maximize benefit of RELRO hardening.
  + Add ufw integration:
    - Created debian/samba.ufw.profile.
    - debian/rules, debian/samba.dirs, debian/samba.files: install
  + Add apoort hook:
    - Created debian/source_samba.py.
    - debian/rules, debian/samba.dirs, debian/samba-common-bin.files: install
  + debian/rules, debian/samba.if-up: allow "NetworkManager" as a recognized address
    family... it's obviously /not/ an address family, but it's what gets
    sent when using NM, so we'll cope for now.  (LP: #462169). Taken from karmic-proposed.
  + debian/control: Recommend keyutils for smbfs (LP: #493565)
  + Dropped patches:
    - debian/patches/security-CVE-2009-3297.patch: No longer needed
    - debian/patches/fix-too-many-open-files.patch: No longer needed

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>idmap_hash</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.74.0"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en"><a name="idmap_hash.8"></a><div class="titlepage"></div><div class="refnamediv"><h2>Name</h2><p>idmap_hash &#8212; Samba's idmap_hash Backend for Winbind</p></div><div class="refsynopsisdiv"><h2>DESCRIPTION</h2><p>The idmap_hash plugin implements a hashing algorithm used to map
 
1
<html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>idmap_hash</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.75.2"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" title="idmap_hash"><a name="idmap_hash.8"></a><div class="titlepage"></div><div class="refnamediv"><h2>Name</h2><p>idmap_hash &#8212; Samba's idmap_hash Backend for Winbind</p></div><div class="refsynopsisdiv" title="DESCRIPTION"><h2>DESCRIPTION</h2><p>The idmap_hash plugin implements a hashing algorithm used to map
2
2
          SIDs for domain users and groups to 31-bit uids and gids, respectively.
3
3
          This plugin also implements the nss_info API and can be used
4
4
          to support a local name mapping files if enabled via the
5
5
          "winbind normalize names" and "winbind nss info"
6
6
          parameters in smb.conf.
7
 
        </p></div><div class="refsect1" lang="en"><a name="id2522931"></a><h2>IDMAP OPTIONS</h2><div class="variablelist"><dl><dt><span class="term">name_map</span></dt><dd><p>
 
7
        </p></div><div class="refsect1" title="IDMAP OPTIONS"><a name="id2528907"></a><h2>IDMAP OPTIONS</h2><div class="variablelist"><dl><dt><span class="term">name_map</span></dt><dd><p>
8
8
                    Specifies the absolute path to the name mapping
9
9
                    file used by the nss_info API.  Entries in the file
10
10
                    are of the form "<em class="replaceable"><code>unix name</code></em>
11
11
                    = <em class="replaceable"><code>qualified domain name</code></em>".
12
12
                    Mapping of both user and group names is supported.
13
 
                </p></dd></dl></div></div><div class="refsect1" lang="en"><a name="id2522963"></a><h2>EXAMPLES</h2><p>The following example utilizes the idmap_hash plugin for
 
13
                </p></dd></dl></div></div><div class="refsect1" title="EXAMPLES"><a name="id2528938"></a><h2>EXAMPLES</h2><p>The following example utilizes the idmap_hash plugin for
14
14
          the idmap and nss_info information.
15
15
        </p><pre class="programlisting">
16
16
        [global]
21
21
        winbind nss info = hash
22
22
        winbind normalize names = yes
23
23
        idmap_hash:name_map = /etc/samba/name_map.cfg
24
 
        </pre></div><div class="refsect1" lang="en"><a name="id2483355"></a><h2>AUTHOR</h2><p>
 
24
        </pre></div><div class="refsect1" title="AUTHOR"><a name="id2489318"></a><h2>AUTHOR</h2><p>
25
25
        The original Samba software and related utilities
26
26
        were created by Andrew Tridgell. Samba is now developed
27
27
        by the Samba Team as an Open Source project similar