summaryrefslogtreecommitdiff
path: root/docs-xml
Commit message (Collapse)AuthorAgeFilesLines
* s3:rpcclient: Implement cmd chpasswd4Andreas Schneider2022-07-281-1/+2
| | | | | | Manually tested against Windows Server 2022. Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs-xml: Remove trailing whitespaces in rpcclient.1.xmlAndreas Schneider2022-07-281-79/+79
| | | | Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs-xml:manpages: update vfs_fileid.8.xml for the recent changesStefan Metzmacher2022-07-051-27/+116
| | | | | | | Signed-off-by: Stefan Metzmacher <metze@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Tue Jul 5 16:01:10 UTC 2022 on sn-devel-184
* vfs_acl_xattr: add acl_xattr:security_acl_name optionRalph Boehme2022-06-271-0/+19
| | | | | Pair-Programmed-With: Jeremy Allison <jra@samba.org> Signed-off-by: Ralph Boehme <slow@samba.org>
* dsdb: Allow password history and password changes without an NT hashAndrew Bartlett2022-06-262-0/+79
| | | | | | | | | | | | | | | | | | | | We now allow this to be via the ENCTYPE_AES256_CTS_HMAC_SHA1_96 hash instead which allows us to decouple Samba from the unsalted NT hash for organisations that are willing to take this step (for user accounts). (History checking is limited to the last three passwords only, as ntPwdHistory is limited to NT hash values, and the PrimaryKerberosCtr4 package only stores three sets of keys.) Since we don't store a salt per-key, but only a single salt, the check will fail for a previous password if the account was renamed prior to a newer password being set. Pair-Programmed-With: Stefan Metzmacher <metze@samba.org> Signed-off-by: Andrew Bartlett <abartlet@samba.org> Signed-off-by: Stefan Metzmacher <metze@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs-xml: add missing generic nfs4 parameters in nfs4_xattr man pageBjörn Jacke2022-06-221-0/+6
| | | | | | | | Signed-off-by: Bjoern Jacke <bjacke@samba.org> Reviewed-by: Christof Schmitt <cs@samba.org> Autobuild-User(master): Christof Schmitt <cs@samba.org> Autobuild-Date(master): Wed Jun 22 18:57:53 UTC 2022 on sn-devel-184
* docs_xml: use the nfs4 parameter include file in zfsacl man pageBjörn Jacke2022-06-221-57/+6
| | | | | Signed-off-by: Bjoern Jacke <bjacke@samba.org> Reviewed-by: Christof Schmitt <cs@samba.org>
* docs_xml: use the nfs4 parameter include file in gpfs man pageBjörn Jacke2022-06-221-56/+8
| | | | | Signed-off-by: Bjoern Jacke <bjacke@samba.org> Reviewed-by: Christof Schmitt <cs@samba.org>
* docs-xml: add nfs4.xml.include documenting the generic NFS4 ACL parametersBjörn Jacke2022-06-221-0/+57
| | | | | Signed-off-by: Bjoern Jacke <bjacke@samba.org> Reviewed-by: Christof Schmitt <cs@samba.org>
* docs: Show current system path for smb.conf in &smb.conf entityAndrew Bartlett2022-06-227-15/+16
| | | | Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
* docs-xml: Use &pathconfig.WINBINDD_SOCKET_DIR; to avoid reference to old ↵Andrew Bartlett2022-06-224-34/+55
| | | | | | | | | | | | /tmp/.winbindd We can now write docs that follow how the software on this system was built, which is much less confusing for users. Also /tmp/.winbindd has not been used for a long time. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15101 Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
* build: Allow &pathconfig XML entities to be used in all manpages, not just ↵Andrew Bartlett2022-06-222-7/+34
| | | | | | | | smb.conf BUG: https://bugzilla.samba.org/show_bug.cgi?id=15101 Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
* s3: VFS: full_audit. Ensure the module doesn't load if an operation name is ↵Jeremy Allison2022-06-171-0/+5
| | | | | | | | | | | miss-spelled or otherwise unknown. Document this new behavior. Remove knownfail. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15098 Signed-off-by: Jeremy Allison <jra@samba.org> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
* spelling: connnect encrytion exisit expection explicit invalide missmatch ↵Michael Tokarev2022-06-108-9/+9
| | | | | | | | | | | | | | | | | | paramater paramter partion privilige relase reponse seperate unkown verson authencication progagated Tree-wide spellcheck for some common misspellings. source3/utils/status.c has misspelled local variable (unkown_dialect). "missmatch" is a known historical misspelling, only the incorrect misspellings are fixed. source3/locale/net/de.po has the spelling error (unkown) in two msgids - it probably should be updated with current source. Signed-off-by: Michael Tokarev <mjt@tls.msk.ru> Reviewed-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* Revert "docs-xml: Update documentation for removal of NIS support"Samuel Cabrero2022-06-095-7/+31
| | | | | | | | | | | This partly reverts commit a72bc3e15d3ed62e9ad2c0a97ce5d6d653abb048. Revert only the chunks related to netgroups and skip NIS related ones. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15087 Signed-off-by: Samuel Cabrero <scabrero@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs-xml: add new parameter volume serial numberChristian Ambach2022-06-061-0/+14
| | | | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14765 RN: add new smb.conf parameter "volume serial number" to allow overriding the generated default value Signed-off-by: Christian Ambach <ambi@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs-xml: document "winbind debug traceid" in smb.confPavel Filipenský2022-05-101-0/+13
| | | | | | Signed-off-by: Pavel Filipenský <pfilipen@redhat.com> Reviewed-by: Andreas Schneider <asn@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs: Explain the impact of "ntlm auth = disabled" on simple bind forwardingAndrew Bartlett2022-05-021-0/+7
| | | | | | | | | | | | | | An RODC will forward an LDAP Simple bind, just like any other authentication, when the password is not present locally. If the full DC does not support NTLMv2 authentication this forwarded password will be rejected. A future Samba version should prefer Kerberos or send the plaintext, but we can not change the MS Windows behaviour, so we document this. BUG: https://bugzilla.samba.org/show_bug.cgi?id=13879 Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
* vfs_fruit: change default for "fruit:zero_file_id" option to yesRalph Boehme2022-03-311-4/+4
| | | | | | | | After discussion with folks at Apple it should be safe these days to rely on the Mac to generate its own File-Ids and let Samba return 0 File-Ids. Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* s4-auth: Remove last traces of LanMan authentiation support in the AD DC.Andrew Bartlett2022-03-291-0/+4
| | | | | | | | Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org> Autobuild-User(master): Andrew Bartlett <abartlet@samba.org> Autobuild-Date(master): Tue Mar 29 03:32:57 UTC 2022 on sn-devel-184
* s4: dns: Add customizable dns port optionThomas Debesse2022-03-251-0/+21
| | | | | | | | | Signed-off-by: Thomas Debesse <dev@illwieckz.net> Reviewed-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Fri Mar 25 20:25:28 UTC 2022 on sn-devel-184
* docs-xml: add 'kdc enable fast' optionStefan Metzmacher2022-03-111-0/+15
| | | | | | | | | | | This will be useful to test against a KDC without FAST support and find/prevent regressions. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15002 BUG: https://bugzilla.samba.org/show_bug.cgi?id=15005 Signed-off-by: Stefan Metzmacher <metze@samba.org> Reviewed-by: Joseph Sutton <josephsutton@catalyst.net.nz>
* docs-xml: Reformat shell scriptsAndreas Schneider2022-02-221-6/+3
| | | | | | shfmt -f docs-xml | xargs shfmt -w -p -i 0 -fn Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
* docs-xml: Fix idmap_autorid documentationAndreas Schneider2022-02-161-1/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | What we want to avoid: $ ./bin/testparm -s | grep "idmap config" idmap config * : rangesize = 10000 idmap config * : range = 10000-19999 idmap config * : backend = autorid $ ./bin/wbinfo --name-to-sid BUILTIN/Administrators S-1-5-32-544 SID_ALIAS (4) $ ./bin/wbinfo --sid-to-gid S-1-5-32-544 10000 $ ./bin/wbinfo --name-to-sid ADDOMAIN/alice S-1-5-21-4058748110-895691256-3682847423-1107 SID_USER (1) $ ./bin/wbinfo --sid-to-gid S-1-5-21-984165912-589366285-3903095728-1107 failed to call wbcSidToGid: WBC_ERR_DOMAIN_NOT_FOUND Could not convert sid S-1-5-21-984165912-589366285-3903095728-1107 to gid If only one range is configured we are either not able to map users/groups from our primary *and* the BUILTIN domain. We need at least two ranges to also cover the BUILTIN domain! BUG: https://bugzilla.samba.org/show_bug.cgi?id=14967 Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Guenther Deschner <gd@samba.org> Autobuild-User(master): Andreas Schneider <asn@cryptomilk.org> Autobuild-Date(master): Wed Feb 16 17:04:53 UTC 2022 on sn-devel-184
* docs-xml:manpages: Document 'dummy' virusfilter and 'virusfilter:infected files'Pavel Filipenský2022-02-101-0/+12
| | | | | | | | Bug: https://bugzilla.samba.org/show_bug.cgi?id=14971 Signed-off-by: Pavel Filipenský <pfilipen@redhat.com> Reviewed-by: Jeremy Allison <jra@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
* s3: smbd: Rename "unix extensions" -> "smb1 unix extensions".Jeremy Allison2022-01-251-3/+4
| | | | | | | | | | | | | Make 'unix extensions' a synonym for "smb1 unix extensions". This will allow us to have a separate "smb2 unix extensions" parameter that we can examine separately. Signed-off-by: Jeremy Allison <jra@samba.org> Reviewed-by: David Mulder <dmulder@suse.com> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Tue Jan 25 21:43:59 UTC 2022 on sn-devel-184
* Remove stray reference to "ldap ssl ads"David Mulder2022-01-041-7/+1
| | | | | | | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14462 "ldap ssl ads" has been deprecated and removed. Signed-off-by: David Mulder <dmulder@suse.com> Reviewed-by: Isaac Boukris <iboukris@gmail.com> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Tue Jan 4 19:58:24 UTC 2022 on sn-devel-184
* pam_winbind: add new pwd_change_prompt option (defaults to off).Günther Deschner2021-12-161-0/+7
| | | | | | | | | | | | | | | | This change disables the prompt for the change of an expired password by default (using the PAM_RADIO_TYPE mechanism if present). BUG: https://bugzilla.samba.org/show_bug.cgi?id=8691 Guenther Signed-off-by: Guenther Deschner <gd@samba.org> Reviewed-by: Alexander Bokovoy <ab@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Thu Dec 16 03:05:30 UTC 2021 on sn-devel-184
* s3:rpc_server: Delete unused code and doc referencesVolker Lendecke2021-12-106-198/+0
| | | | | | | Signed-off-by: Volker Lendecke <vl@samba.org> Reviewed-by: Samuel Cabrero <scabrero@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* s3:rpc_server: Add samba-dcerpcdVolker Lendecke2021-12-102-0/+211
| | | | | | | | | | | | | | | | | | | | | | | | | Central dispatcher for incoming RPC requests, supported by helpers that implement RPC services. Upon startup, it asks all helpers which interfaces and endpoints to listen on so it doesn't interfere with the samba binary when we're configured as an Active Directory Domain Controller, then samba-dcerpcd opens the relevant sockets. Once clients connect, start required helpers and tell them to shut down once idle for a while. Can be started as a full standalone daemon without smbd involved or as a helper daemon started on demand by smbd or winbind or other local processes trying to connect to a named pipe based RPC service. NB. To start as a standalone daemon the smb.conf [global] option "rpc start on demand helpers = false" must be set. By default "rpc start on demand helpers = true" in order to allow upgrades without needing an smb.conf change. Signed-off-by: Volker Lendecke <vl@samba.org> Reviewed-by: Samuel Cabrero <scabrero@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs-xml: Add "rpc start on demand helpers", true by default.Jeremy Allison2021-12-101-0/+22
| | | | | | | | | | | If "true" allow smbd and winbindd to spawn samba-dcerpcd as a named pipe helper. Allows upgrade without any change to smb.conf. If samba-dcerpcd is run as a daemon this must be set to "false". Signed-off-by: Jeremy Allison <jra@samba.org> Reviewed-by: Volker Lendecke <vl@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs: fix documentation for default of "fruit:zero_file_id"Ralph Boehme2021-12-061-1/+1
| | | | | | | | | | | | | This got changed by 6e65c283120e3e627f0d8570601263f904529996 without updating the manpage. BUG: https://bugzilla.samba.org/show_bug.cgi?id=14926 Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Mon Dec 6 18:24:24 UTC 2021 on sn-devel-184
* smb.conf.5: Fix a typo for "username map script"Volker Lendecke2021-11-111-1/+1
| | | | | Signed-off-by: Volker Lendecke <vl@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs-xml: Fix smbget manpageAndreas Schneider2021-11-111-1/+5
| | | | | | | | | | There is no &stdarg.encrypt anymore. Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Ralph Boehme <slow@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Thu Nov 11 16:27:12 UTC 2021 on sn-devel-184
* CVE-2020-25717: Add FreeIPA domain controller roleAlexander Bokovoy2021-11-091-0/+7
| | | | | | | | | | | | | | | | | As we want to reduce use of 'classic domain controller' role but FreeIPA relies on it internally, add a separate role to mark FreeIPA domain controller role. It means that role won't result in ROLE_STANDALONE. BUG: https://bugzilla.samba.org/show_bug.cgi?id=14801 BUG: https://bugzilla.samba.org/show_bug.cgi?id=14556 Pair-Programmed-With: Stefan Metzmacher <metze@samba.org> Signed-off-by: Alexander Bokovoy <ab@samba.org> Signed-off-by: Stefan Metzmacher <metze@samba.org> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
* CVE-2020-25717: loadparm: Add new parameter "min domain uid"Samuel Cabrero2021-11-092-0/+21
| | | | | | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14801 BUG: https://bugzilla.samba.org/show_bug.cgi?id=14556 Pair-Programmed-With: Stefan Metzmacher <metze@samba.org> Signed-off-by: Samuel Cabrero <scabrero@samba.org> Signed-off-by: Stefan Metzmacher <metze@samba.org> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
* debug: Add new smb.conf option "debug syslog format"Martin Schwenke2021-11-012-1/+23
| | | | | | | | Signed-off-by: Martin Schwenke <martin@meltin.net> Reviewed-by: Ralph Boehme <slow@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Mon Nov 1 07:29:47 UTC 2021 on sn-devel-184
* s3: docs-xml: Clarify the "delete veto files" paramter.Jeremy Allison2021-10-291-3/+6
| | | | | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14879 Signed-off-by: Jeremy Allison <jra@samba.org> Reviewed-by: Ralph Boehme <slow@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Fri Oct 29 14:57:14 UTC 2021 on sn-devel-184
* docs: document new Spotlight Elasticsearch optionsRalph Boehme2021-10-142-0/+38
| | | | | | | | | | | elasticsearch:ignore unknown attribute = yes | no (default: no) elasticsearch:ignore unknown type = yes | no (default: no) Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Noel Power <npower@samba.org> Autobuild-User(master): Noel Power <npower@samba.org> Autobuild-Date(master): Thu Oct 14 10:20:27 UTC 2021 on sn-devel-184
* docs-xml: Use /var/tmp for spooling in smb.conf.5Andreas Schneider2021-10-121-2/+2
| | | | | | | | | | | This is a world writeable directory which exists on Linux distributions by default already. Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Ralph Boehme <slow@samba.org> Autobuild-User(master): Andreas Schneider <asn@cryptomilk.org> Autobuild-Date(master): Tue Oct 12 17:24:01 UTC 2021 on sn-devel-184
* docs-xml: Remove trailing spaces in smb.conf.5.xmlAndreas Schneider2021-10-121-62/+62
| | | | Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Ralph Boehme <slow@samba.org>
* docs-xml: Update winbindd(8) manpagePavel Filipenský2021-10-121-1/+19
| | | | | | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14852 Signed-off-by: Pavel Filipenský <pfilipen@redhat.com> Reviewed-by: Ralph Boehme <slow@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Tue Oct 12 09:30:02 UTC 2021 on sn-devel-184
* libcli/dns: dns forwarder port doc changesMatthew Grant2021-09-281-2/+6
| | | | | | | | | Documentation changes specifying how list entries for dns forwarder are to be specified with ability to add trailing target port number. Signed-off-by: Matthew Grant <grantma@mattgrant.net.nz> Reviewed-by: Uri Simchoni <uri@samba.org> Reviewed-by: Andrew Bartlett <abartlet@samba.org>
* docs-xml: Update vfs_full_audit manpage for renamed functionChristof Schmitt2021-09-211-1/+1
| | | | | Signed-off-by: Christof Schmitt <cs@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs-xml: Update manpage for "kernel share modes" optionChristof Schmitt2021-09-141-7/+8
| | | | | Signed-off-by: Christof Schmitt <cs@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* lib/cmdline: restore s3 option name --max-protocol for MAXPROTOCOL from 4.14Ralph Boehme2021-09-1010-12/+12
| | | | | | | | | | s4 used --maxprotocol, s3 used --max-protocol. We should continue supporting --max-protocol. BUG: https://bugzilla.samba.org/show_bug.cgi?id=14828 Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* manpages: remove duplicate options from smbclientRalph Boehme2021-09-101-47/+0
| | | | | | | BUG: https://bugzilla.samba.org/show_bug.cgi?id=14828 Signed-off-by: Ralph Boehme <slow@samba.org> Reviewed-by: Stefan Metzmacher <metze@samba.org>
* docs: Avoid duplicate information on USER and PASSWD, reference the common ↵Andrew Bartlett2021-09-091-10/+4
| | | | | | | | | | | | section BUG: https://bugzilla.samba.org/show_bug.cgi?id=14791 Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org> Autobuild-User(master): Jeremy Allison <jra@samba.org> Autobuild-Date(master): Thu Sep 9 00:52:09 UTC 2021 on sn-devel-184
* docs: Document all the other ways to send a password to smbclient et alAndrew Bartlett2021-09-091-11/+41
| | | | | | | | | | This was previously hidden knowlege not easily available to administrators and end users. BUG: https://bugzilla.samba.org/show_bug.cgi?id=14791 Signed-off-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Jeremy Allison <jra@samba.org>
* docs-xml: use upper case for "{client,server} smb3 {signing,encryption} ↵Stefan Metzmacher2021-09-084-18/+18
| | | | | | | | | | | | | | | | algorithms" values This matches what smbstatus prints out. Note there's also the removal of an '-' in "hmac-sha-256" => HMAC-SHA256". BUG: https://bugzilla.samba.org/show_bug.cgi?id=14825 RN: "{client,server} smb3 {signing,encryption} algorithms" should use the same strings as smbstatus output Signed-off-by: Stefan Metzmacher <metze@samba.org> Reviewed-by: Ralph Boehme <slow@samba.org> Autobuild-User(master): Ralph Böhme <slow@samba.org> Autobuild-Date(master): Wed Sep 8 16:37:07 UTC 2021 on sn-devel-184