2
.TH AUTOFS_LDAP_AUTH.CONF 5 "19 Feb 2010"
4
autofs_ldap_auth.conf \- autofs LDAP authentication configuration
6
LDAP authenticated binds, TLS encrypted connections and certification
7
may be used by setting appropriate values in the autofs authentication
8
configuration file and configuring the LDAP client with appropriate
9
settings. The default location of this file is
11
.BR @@autofsmapdir@@/autofs_ldap_auth.conf .
13
If this file exists it will be used to establish whether TLS or authentication
16
An example of this file is:
21
<?xml version="1.0" ?>
22
<autofs_ldap_sasl_conf
33
If TLS encryption is to be used the location of the Certificate Authority
34
certificate must be set within the LDAP client configuration in
35
order to validate the server certificate. If, in addition, a certified
36
connection is to be used then the client certificate and private key file
37
locations must also be configured within the LDAP client.
39
This files contains a single XML element, as shown in the example above, with
42
The possible attributes are:
44
\fBusetls="yes"|"no"\fP
45
Determines whether an encrypted connection to the ldap server
48
\fBtlsrequired="yes"|"no"\fP
49
This flag tells whether the ldap connection must be encrypted. If set to "yes",
50
the automounter will fail to start if an encrypted connection cannot be
53
\fBauthrequired="yes"|"no"|"autodetect"|"simple"\fP
54
This option tells whether an authenticated connection to the ldap server is
55
required in order to perform ldap queries. If the flag is set to yes, only
56
sasl authenticated connections will be allowed. If it is set to no then
57
authentication is not needed for ldap server connections. If it is set to
58
autodetect then the ldap server will be queried to establish a suitable sasl
59
authentication mechanism. If no suitable mechanism can be found, connections
60
to the ldap server are made without authentication. Finally, if it is set to
61
simple, then simple authentication will be used instead of SASL.
63
\fBauthtype="GSSAPI"|"LOGIN"|"PLAIN"|"ANONYMOUS"|"DIGEST-MD5"\fP
64
This attribute can be used to specify a preferred authentication mechanism.
65
In normal operations, the automounter will attempt to authenticate to the
66
ldap server using the list of supportedSASLmechanisms obtained from the
67
directory server. Explicitly setting the authtype will bypass this selection
68
and only try the mechanism specified.
70
\fBuser="<username>"\fP
71
This attribute holds the authentication identity used by authentication
72
mechanisms that require it. Legal values for this attribute include any
73
printable characters that can be used by the selected authentication
76
\fBsecret="<password>"\fP
77
This attribute holds the secret used by authentication mechanisms that
78
require it. Legal values for this attribute include any printable
79
characters that can be used by the selected authentication mechanism.
81
\fBclientprinc="<GSSAPI client principal>"\fP
82
When using GSSAPI authentication, this attribute is consulted to determine
83
the principal name to use when authenticating to the directory server. By
84
default, this will be set to "autofsclient/<fqdn>@<REALM>.
86
\fBcredentialcache="<external credential cache path>"\fP
87
When using GSSAPI authentication, this attribute can be used to specify an
88
externally configured credential cache that is used during authentication.
89
By default, autofs will setup a memory based credential cache.
93
This manual page was written by Ian Kent <raven@themaw.net>.